2025-05-07T18:01:04Z DEBUG Logging to /var/log/ipaserver-install.log 2025-05-07T18:01:04Z DEBUG ipa-server-install was invoked with arguments [] and options: {'unattended': True, 'ip_addresses': None, 'domain_name': 'ufreeipa.test', 'realm_name': 'UFREEIPA.TEST', 'host_name': None, 'ca_cert_files': None, 'domain_level': 1, 'setup_adtrust': False, 'setup_kra': False, 'setup_dns': True, 'idstart': None, 'idmax': None, 'no_hbac_allow': False, 'no_pkinit': False, 'no_ui_redirect': False, 'dirsrv_config_file': '/root/ipatests/ipatests_dse.ldif', 'skip_mem_check': False, 'dirsrv_cert_files': None, 'http_cert_files': None, 'pkinit_cert_files': None, 'dirsrv_cert_name': None, 'http_cert_name': None, 'pkinit_cert_name': None, 'token_name': None, 'token_library_path': None, 'token_password_file': None, 'mkhomedir': False, 'ntp_servers': None, 'ntp_pool': None, 'no_ntp': False, 'force_ntpd': False, 'ssh_trust_dns': False, 'no_ssh': False, 'no_sshd': False, 'subid': False, 'no_dns_sshfp': False, 'dns_over_tls': False, 'external_ca': False, 'external_ca_type': None, 'external_ca_profile': None, 'external_cert_files': None, 'subject_base': None, 'ca_subject': None, 'ca_signing_algorithm': None, 'random_serial_numbers': False, 'pki_config_override': None, 'allow_zone_overlap': False, 'reverse_zones': None, 'no_reverse': False, 'auto_reverse': True, 'zonemgr': None, 'forwarders': [CheckedIPAddressLoopback('10.11.5.19')], 'no_forwarders': False, 'auto_forwarders': False, 'forward_policy': None, 'no_dnssec_validation': False, 'dot_forwarders': None, 'dns_over_tls_cert': None, 'dns_over_tls_key': None, 'dns_policy': None, 'no_host_dns': False, 'enable_compat': False, 'no_msdcs': False, 'netbios_name': None, 'rid_base': None, 'secondary_rid_base': None, 'ignore_topology_disconnect': False, 'ignore_last_of_role': False, 'verbose': False, 'quiet': False, 'log_file': None, 'uninstall': False} 2025-05-07T18:01:04Z DEBUG IPA version 4.13.0.dev202505071340+git-0.fc42 2025-05-07T18:01:04Z DEBUG IPA platform fedora 2025-05-07T18:01:04Z DEBUG IPA os-release Fedora Linux 42 (Cloud Edition) 2025-05-07T18:01:05Z DEBUG svmem(total=4093968384, available=3507310592, percent=14.3, used=309202944, free=1205248000, active=275292160, inactive=2329112576, buffers=5849088, cached=2573668352, shared=5410816, slab=203350016) 2025-05-07T18:01:05Z DEBUG Available memory is 3507310592B 2025-05-07T18:01:05Z DEBUG Searching for an interface of IP address: ::1 2025-05-07T18:01:05Z DEBUG Testing local IP address: ::1/128 (interface: lo) 2025-05-07T18:01:05Z DEBUG Starting external process 2025-05-07T18:01:05Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:01:05Z DEBUG Process finished, return code=0 2025-05-07T18:01:05Z DEBUG stdout= 2025-05-07T18:01:05Z DEBUG stderr= 2025-05-07T18:01:05Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:01:05Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:01:05Z DEBUG httpd is not configured 2025-05-07T18:01:05Z DEBUG kadmin is not configured 2025-05-07T18:01:05Z DEBUG dirsrv is not configured 2025-05-07T18:01:05Z DEBUG pki-tomcatd is not configured 2025-05-07T18:01:05Z DEBUG install is not configured 2025-05-07T18:01:05Z DEBUG krb5kdc is not configured 2025-05-07T18:01:05Z DEBUG named is not configured 2025-05-07T18:01:05Z DEBUG filestore is tracking no files 2025-05-07T18:01:05Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-05-07T18:01:05Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-05-07T18:01:05Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-05-07T18:01:05Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:01:05Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:01:05Z DEBUG Starting external process 2025-05-07T18:01:05Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2025-05-07T18:01:05Z DEBUG Process finished, return code=4 2025-05-07T18:01:05Z DEBUG stdout=not-found 2025-05-07T18:01:05Z DEBUG stderr= 2025-05-07T18:01:05Z DEBUG Starting external process 2025-05-07T18:01:05Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2025-05-07T18:01:05Z DEBUG Process finished, return code=4 2025-05-07T18:01:05Z DEBUG stdout=inactive 2025-05-07T18:01:05Z DEBUG stderr= 2025-05-07T18:01:05Z DEBUG Starting external process 2025-05-07T18:01:05Z DEBUG args=['/bin/systemctl', 'is-enabled', 'systemd-timesyncd.service'] 2025-05-07T18:01:05Z DEBUG Process finished, return code=1 2025-05-07T18:01:05Z DEBUG stdout=disabled 2025-05-07T18:01:05Z DEBUG stderr= 2025-05-07T18:01:05Z DEBUG Starting external process 2025-05-07T18:01:05Z DEBUG args=['/bin/systemctl', 'is-active', 'systemd-timesyncd.service'] 2025-05-07T18:01:05Z DEBUG Process finished, return code=3 2025-05-07T18:01:05Z DEBUG stdout=inactive 2025-05-07T18:01:05Z DEBUG stderr= 2025-05-07T18:01:05Z DEBUG Check if master.ufreeipa.test is a primary hostname for localhost 2025-05-07T18:01:05Z DEBUG Primary hostname for localhost: master.ufreeipa.test 2025-05-07T18:01:05Z DEBUG will use host_name: master.ufreeipa.test 2025-05-07T18:01:05Z DEBUG Writing configuration file /etc/ipa/default.conf 2025-05-07T18:01:05Z DEBUG [global] host = master.ufreeipa.test basedn = dc=ufreeipa,dc=test realm = UFREEIPA.TEST domain = ufreeipa.test xmlrpc_uri = https://master.ufreeipa.test/ipa/xml ldap_uri = ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket mode = production enable_ra = True ra_plugin = dogtag dogtag_version = 10 2025-05-07T18:01:05Z DEBUG importing all plugin modules in ipaserver.plugins... 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.aci 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.automember 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.automount 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.baseldap 2025-05-07T18:01:05Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.baseuser 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.batch 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.ca 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.caacl 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.cert 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.certmap 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.certprofile 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.config 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.delegation 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.dns 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.dogtag 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.group 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.hbac 2025-05-07T18:01:05Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.hbactest 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.host 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.idp 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.idrange 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.idviews 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.internal 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.join 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.ldap2 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.location 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.migration 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.misc 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.netgroup 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.otp 2025-05-07T18:01:05Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.otptoken 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.passkeyconfig 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.passwd 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.permission 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.ping 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.pkinit 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.privilege 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.rabase 2025-05-07T18:01:05Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.role 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.schema 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.selfservice 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.server 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.serverrole 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.serverroles 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.service 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.session 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.stageuser 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.subid 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.sudo 2025-05-07T18:01:05Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.sudorule 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.topology 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.trust 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.user 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.vault 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.virtual 2025-05-07T18:01:05Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.whoami 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2025-05-07T18:01:05Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.dns 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_subid_support 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2025-05-07T18:01:05Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2025-05-07T18:01:05Z DEBUG check_port_bindable: Checking IPv4/IPv6 dual stack and TCP 2025-05-07T18:01:05Z DEBUG check_port_bindable: bind success: 8443/TCP 2025-05-07T18:01:05Z DEBUG check_port_bindable: Checking IPv4/IPv6 dual stack and TCP 2025-05-07T18:01:05Z DEBUG check_port_bindable: bind success: 8080/TCP 2025-05-07T18:01:05Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:01:05Z INFO Checking DNS domain ufreeipa.test., please wait ... 2025-05-07T18:01:17Z DEBUG Name master.ufreeipa.test resolved to {UnsafeIPAddress('10.0.169.172')} 2025-05-07T18:01:17Z DEBUG Searching for an interface of IP address: 10.0.169.172 2025-05-07T18:01:17Z DEBUG Testing local IP address: 127.0.0.1/8 (interface: lo) 2025-05-07T18:01:17Z DEBUG Testing local IP address: 10.0.169.172/24 (interface: enp3s0) 2025-05-07T18:01:17Z DEBUG IP address 10.0.169.172 belongs to a private range, using forward policy only 2025-05-07T18:01:17Z DEBUG Checking DNS server: 10.11.5.19 2025-05-07T18:01:17Z DEBUG will use DNS forwarders: [CheckedIPAddressLoopback('10.11.5.19')] 2025-05-07T18:01:29Z INFO Reverse record for IP address 10.0.169.172 already exists 2025-05-07T18:01:29Z DEBUG LDAP is not connected, can not retrieve NetBIOS name 2025-05-07T18:01:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:01:29Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:01:29Z DEBUG Backing up system configuration file '/etc/hosts' 2025-05-07T18:01:29Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:01:29Z DEBUG Starting external process 2025-05-07T18:01:29Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:01:29Z DEBUG Process finished, return code=0 2025-05-07T18:01:29Z DEBUG stdout= 2025-05-07T18:01:29Z DEBUG stderr= 2025-05-07T18:01:29Z DEBUG Starting external process 2025-05-07T18:01:29Z DEBUG args=['/sbin/restorecon', '/etc/pkcs11/modules/softhsm2.module'] 2025-05-07T18:01:29Z DEBUG Process finished, return code=0 2025-05-07T18:01:29Z DEBUG stdout= 2025-05-07T18:01:29Z DEBUG stderr= 2025-05-07T18:01:29Z DEBUG Created PKCS#11 module config '/etc/pkcs11/modules/softhsm2.module'. 2025-05-07T18:01:29Z DEBUG Starting external process 2025-05-07T18:01:29Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2025-05-07T18:01:29Z DEBUG Process finished, return code=4 2025-05-07T18:01:29Z DEBUG stdout=not-found 2025-05-07T18:01:29Z DEBUG stderr= 2025-05-07T18:01:29Z DEBUG Starting external process 2025-05-07T18:01:29Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2025-05-07T18:01:29Z DEBUG Process finished, return code=4 2025-05-07T18:01:29Z DEBUG stdout=inactive 2025-05-07T18:01:29Z DEBUG stderr= 2025-05-07T18:01:29Z DEBUG Starting external process 2025-05-07T18:01:29Z DEBUG args=['/bin/systemctl', 'is-enabled', 'systemd-timesyncd.service'] 2025-05-07T18:01:29Z DEBUG Process finished, return code=1 2025-05-07T18:01:29Z DEBUG stdout=disabled 2025-05-07T18:01:29Z DEBUG stderr= 2025-05-07T18:01:29Z DEBUG Starting external process 2025-05-07T18:01:29Z DEBUG args=['/bin/systemctl', 'is-active', 'systemd-timesyncd.service'] 2025-05-07T18:01:29Z DEBUG Process finished, return code=3 2025-05-07T18:01:29Z DEBUG stdout=inactive 2025-05-07T18:01:29Z DEBUG stderr= 2025-05-07T18:01:29Z DEBUG Search DNS for SRV record of _ntp._udp.None 2025-05-07T18:01:53Z DEBUG DNS record not found: NXDOMAIN 2025-05-07T18:01:53Z INFO Synchronizing time 2025-05-07T18:01:53Z WARNING No SRV records of NTP servers found and no NTP server or pool address was provided. 2025-05-07T18:01:53Z DEBUG Starting external process 2025-05-07T18:01:53Z DEBUG args=['/bin/systemctl', 'enable', 'chronyd.service'] 2025-05-07T18:01:54Z DEBUG Process finished, return code=0 2025-05-07T18:01:54Z DEBUG stdout= 2025-05-07T18:01:54Z DEBUG stderr= 2025-05-07T18:01:54Z DEBUG Starting external process 2025-05-07T18:01:54Z DEBUG args=['/bin/systemctl', 'restart', 'chronyd.service'] 2025-05-07T18:01:54Z DEBUG Process finished, return code=0 2025-05-07T18:01:54Z DEBUG stdout= 2025-05-07T18:01:54Z DEBUG stderr= 2025-05-07T18:01:54Z DEBUG Starting external process 2025-05-07T18:01:54Z DEBUG args=['/bin/systemctl', 'is-active', 'chronyd.service'] 2025-05-07T18:01:54Z DEBUG Process finished, return code=0 2025-05-07T18:01:54Z DEBUG stdout=active 2025-05-07T18:01:54Z DEBUG stderr= 2025-05-07T18:01:54Z DEBUG Restart of chronyd.service complete 2025-05-07T18:01:54Z INFO Attempting to sync time with chronyc. 2025-05-07T18:01:54Z DEBUG Starting external process 2025-05-07T18:01:54Z DEBUG args=['/usr/bin/chronyc', '-d', 'waitsync', '4', '0', '0', '3'] 2025-05-07T18:02:03Z DEBUG Process finished, return code=1 2025-05-07T18:02:03Z DEBUG stdout=try: 1, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 2, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 3, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 4, refid: 00000000, correction: 0.000000000, skew: 0.000 2025-05-07T18:02:03Z DEBUG stderr=Resolved 127.0.0.1 to 127.0.0.1 Resolved ::1 to ::1 Could not remove /run/chrony/chronyc.24181.sock : No such file or directory Opened Unix socket fd=3 remote=/run/chrony/chronyd.sock local=/run/chrony/chronyc.24181.sock Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 2025-05-07T18:02:03Z WARNING Process chronyc waitsync failed to sync time! 2025-05-07T18:02:03Z WARNING Unable to sync time with chrony server, assuming the time is in sync. Please check that 123 UDP port is opened, and any time server is on network. 2025-05-07T18:02:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:03Z DEBUG Configuring directory server (dirsrv). Estimated time: 30 seconds 2025-05-07T18:02:03Z DEBUG [1/45]: creating directory server instance 2025-05-07T18:02:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:03Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:03Z DEBUG Running setup with verbose 2025-05-07T18:02:03Z DEBUG START: Starting installation ... 2025-05-07T18:02:03Z DEBUG READY: Preparing installation for UFREEIPA-TEST... 2025-05-07T18:02:03Z INFO Validate installation settings ... 2025-05-07T18:02:03Z DEBUG PASSED: using config settings 999999999 2025-05-07T18:02:03Z DEBUG PASSED: user / group checking 2025-05-07T18:02:03Z DEBUG PASSED: prefix checking 2025-05-07T18:02:03Z DEBUG list() UFREEIPA-TEST instance not found: missing /etc/dirsrv/slapd-UFREEIPA-TEST/dse.ldif 2025-05-07T18:02:03Z DEBUG PASSED: instance checking 2025-05-07T18:02:03Z DEBUG INFO: temp root password set to N16jpiCzMgEj4SPPCOLzW.2g9vF9zYeCTYql8xcLE.sGGzP6tIYESnuYEuCFz.mT4 2025-05-07T18:02:03Z DEBUG PASSED: root user checking 2025-05-07T18:02:03Z DEBUG PASSED: network avaliability checking 2025-05-07T18:02:03Z DEBUG READY: Beginning installation for UFREEIPA-TEST... 2025-05-07T18:02:03Z DEBUG ACTION: Creating dse.ldif 2025-05-07T18:02:03Z INFO Create file system structures ... 2025-05-07T18:02:03Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:02:03Z DEBUG ACTION: creating /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:03Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-UFREEIPA-TEST/db 2025-05-07T18:02:03Z DEBUG ACTION: creating /dev/shm/slapd-UFREEIPA-TEST 2025-05-07T18:02:03Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:02:03Z DEBUG ACTION: creating /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:03Z DEBUG ACTION: creating /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:03Z DEBUG ACTION: creating /run/dirsrv 2025-05-07T18:02:03Z DEBUG b"CMD: systemctl enable dirsrv@UFREEIPA-TEST ; STDOUT: ; STDERR: Created symlink '/etc/systemd/system/multi-user.target.wants/dirsrv@UFREEIPA-TEST.service' \xe2\x86\x92 '/usr/lib/systemd/system/dirsrv@.service'.\n" 2025-05-07T18:02:03Z DEBUG ACTION: Creating certificate database is /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:03Z DEBUG Allocate with None 2025-05-07T18:02:03Z DEBUG Allocate with /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:02:03Z DEBUG Allocate with localhost:389 2025-05-07T18:02:03Z DEBUG Allocate with localhost:389 2025-05-07T18:02:03Z DEBUG nss cmd: /usr/bin/certutil -N -d /etc/dirsrv/slapd-UFREEIPA-TEST -f /etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt -@ /etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt 2025-05-07T18:02:03Z DEBUG nss output: 2025-05-07T18:02:03Z INFO Perform SELinux labeling ... 2025-05-07T18:02:03Z DEBUG port 389 already in [389, 636, 3268, 3269, 7389], skipping port relabel 2025-05-07T18:02:03Z DEBUG asan_enabled=False 2025-05-07T18:02:03Z DEBUG libfaketime installed =False 2025-05-07T18:02:03Z DEBUG systemd status -> True 2025-05-07T18:02:03Z DEBUG systemd status -> True 2025-05-07T18:02:04Z DEBUG open(): Connecting to uri ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket 2025-05-07T18:02:04Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:04Z DEBUG Using external ca certificate /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:04Z DEBUG Using /etc/openldap/ldap.conf certificate policy 2025-05-07T18:02:04Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 2 2025-05-07T18:02:04Z DEBUG open(): Using root autobind ... 2025-05-07T18:02:04Z DEBUG open(): bound as cn=Directory Manager 2025-05-07T18:02:04Z DEBUG Retrieving entry with [('',)] 2025-05-07T18:02:04Z DEBUG Retrieved entry [dn: vendorVersion: 389-Directory/3.1.2 B2025.045.0000 ] 2025-05-07T18:02:04Z DEBUG open(): Connecting to uri ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket 2025-05-07T18:02:04Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:04Z DEBUG Using external ca certificate /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:04Z DEBUG Using /etc/openldap/ldap.conf certificate policy 2025-05-07T18:02:04Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 2 2025-05-07T18:02:04Z DEBUG open(): Using root autobind ... 2025-05-07T18:02:04Z DEBUG open(): bound as cn=Directory Manager 2025-05-07T18:02:04Z DEBUG Retrieving entry with [('',)] 2025-05-07T18:02:04Z DEBUG Retrieved entry [dn: vendorVersion: 389-Directory/3.1.2 B2025.045.0000 ] 2025-05-07T18:02:04Z DEBUG cn=config set REPLACE: ('nsslapd-secureport', '636') 2025-05-07T18:02:04Z DEBUG cn=config,cn=ldbm database,cn=plugins,cn=config getVal('nsslapd-backend-implement') 2025-05-07T18:02:04Z DEBUG cn=mdb,cn=config,cn=ldbm database,cn=plugins,cn=config set REPLACE: ('nsslapd-mdb-max-size', '21474836480') 2025-05-07T18:02:04Z DEBUG Checking "None" under cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config : {'cn': 'entryUUID', 'nsSystemIndex': 'false', 'nsIndexType': ['eq', 'pres']} 2025-05-07T18:02:04Z DEBUG Using first property cn: entryUUID as rdn 2025-05-07T18:02:04Z DEBUG Validated dn cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:04Z DEBUG Creating cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:04Z DEBUG updating dn: cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:04Z DEBUG updated dn: cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config with {'objectclass': [b'top', b'nsIndex']} 2025-05-07T18:02:04Z DEBUG updating dn: cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:04Z DEBUG updated dn: cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config with {'cn': [b'entryUUID'], 'nsSystemIndex': [b'false'], 'nsIndexType': [b'eq', b'pres']} 2025-05-07T18:02:04Z DEBUG Created entry cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config : {'objectclass': [b'top', b'nsIndex'], 'cn': [b'entryUUID'], 'nsSystemIndex': [b'false'], 'nsIndexType': [b'eq', b'pres']} 2025-05-07T18:02:04Z INFO Create database backend: dc=ufreeipa,dc=test ... 2025-05-07T18:02:05Z DEBUG Checking "None" under cn=ldbm database,cn=plugins,cn=config : {'cn': 'userRoot', 'nsslapd-suffix': 'dc=ufreeipa,dc=test'} 2025-05-07T18:02:05Z DEBUG Using first property cn: userRoot as rdn 2025-05-07T18:02:05Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=dc=ufreeipa,dc=test)(nsslapd-backend=dc=ufreeipa,dc=test))) 2025-05-07T18:02:05Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=userRoot)(nsslapd-backend=userRoot))) 2025-05-07T18:02:05Z DEBUG Validated dn cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:05Z DEBUG Creating cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:05Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:05Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance']} 2025-05-07T18:02:05Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:05Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=ufreeipa,dc=test']} 2025-05-07T18:02:05Z DEBUG Created entry cn=userRoot,cn=ldbm database,cn=plugins,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance'], 'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=ufreeipa,dc=test']} 2025-05-07T18:02:05Z DEBUG Checking "None" under cn=mapping tree,cn=config : {'cn': [b'dc=ufreeipa,dc=test'], 'nsslapd-state': 'backend', 'nsslapd-backend': [b'userRoot']} 2025-05-07T18:02:05Z DEBUG Using first property cn: dc\=ufreeipa\,dc\=test as rdn 2025-05-07T18:02:05Z DEBUG Validated dn cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config 2025-05-07T18:02:05Z DEBUG Creating cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config 2025-05-07T18:02:05Z DEBUG updating dn: cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config 2025-05-07T18:02:05Z DEBUG updated dn: cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree']} 2025-05-07T18:02:05Z DEBUG updating dn: cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config 2025-05-07T18:02:05Z DEBUG updated dn: cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config with {'cn': [b'dc=ufreeipa,dc=test', b'dc\\=ufreeipa\\,dc\\=test'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2025-05-07T18:02:05Z DEBUG Created entry cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree'], 'cn': [b'dc=ufreeipa,dc=test', b'dc\\=ufreeipa\\,dc\\=test'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2025-05-07T18:02:05Z DEBUG Adding sasl maps for suffix dc=ufreeipa,dc=test 2025-05-07T18:02:05Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'rfc 2829 u syntax', 'nsSaslMapRegexString': '^u:\\(.*\\)', 'nsSaslMapBaseDNTemplate': 'dc=ufreeipa,dc=test', 'nsSaslMapFilterTemplate': '(uid=\\1)'} 2025-05-07T18:02:05Z DEBUG Using first property cn: rfc 2829 u syntax as rdn 2025-05-07T18:02:05Z DEBUG Validated dn cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2025-05-07T18:02:05Z DEBUG Creating cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2025-05-07T18:02:05Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2025-05-07T18:02:05Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2025-05-07T18:02:05Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2025-05-07T18:02:05Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=ufreeipa,dc=test'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2025-05-07T18:02:05Z DEBUG Created entry cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=ufreeipa,dc=test'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2025-05-07T18:02:05Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'uid mapping', 'nsSaslMapRegexString': '^[^:@]+$', 'nsSaslMapBaseDNTemplate': 'dc=ufreeipa,dc=test', 'nsSaslMapFilterTemplate': '(uid=&)'} 2025-05-07T18:02:05Z DEBUG Using first property cn: uid mapping as rdn 2025-05-07T18:02:05Z DEBUG Validated dn cn=uid mapping,cn=mapping,cn=sasl,cn=config 2025-05-07T18:02:05Z DEBUG Creating cn=uid mapping,cn=mapping,cn=sasl,cn=config 2025-05-07T18:02:05Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2025-05-07T18:02:05Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2025-05-07T18:02:05Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2025-05-07T18:02:05Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=ufreeipa,dc=test'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2025-05-07T18:02:05Z DEBUG Created entry cn=uid mapping,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=ufreeipa,dc=test'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2025-05-07T18:02:05Z INFO Perform post-installation tasks ... 2025-05-07T18:02:05Z DEBUG cn=config set REPLACE: ('nsslapd-rootpw', '********') 2025-05-07T18:02:05Z DEBUG systemd status -> True 2025-05-07T18:02:05Z DEBUG systemd status -> True 2025-05-07T18:02:06Z DEBUG systemd status -> True 2025-05-07T18:02:06Z DEBUG systemd status -> True 2025-05-07T18:02:07Z DEBUG 🎉 Instance setup complete 2025-05-07T18:02:07Z DEBUG FINISH: Completed installation for instance: slapd-UFREEIPA-TEST 2025-05-07T18:02:07Z DEBUG Allocate local instance with ldapi://%2fvar%2frun%2fslapd-UFREEIPA-TEST.socket 2025-05-07T18:02:07Z DEBUG open(): Connecting to uri ldapi://%2fvar%2frun%2fslapd-UFREEIPA-TEST.socket 2025-05-07T18:02:07Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:07Z DEBUG Using external ca certificate /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:02:07Z DEBUG Using /etc/openldap/ldap.conf certificate policy 2025-05-07T18:02:07Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 2 2025-05-07T18:02:07Z DEBUG open(): Using root autobind ... 2025-05-07T18:02:07Z DEBUG open(): bound as cn=Directory Manager 2025-05-07T18:02:07Z DEBUG Retrieving entry with [('',)] 2025-05-07T18:02:07Z DEBUG Retrieved entry [dn: vendorVersion: 389-Directory/3.1.2 B2025.045.0000 ] 2025-05-07T18:02:07Z DEBUG Retrieving entry with [('cn=Multisupplier Replication Plugin,cn=plugins,cn=config',)] 2025-05-07T18:02:07Z DEBUG Retrieved entry [dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config cn: Multisupplier Replication Plugin ] 2025-05-07T18:02:07Z DEBUG Checking "None" under None : {'dc': 'ufreeipa', 'info': 'IPA V2.0'} 2025-05-07T18:02:07Z DEBUG Validated dn dc=ufreeipa,dc=test 2025-05-07T18:02:07Z DEBUG Creating dc=ufreeipa,dc=test 2025-05-07T18:02:07Z DEBUG updating dn: dc=ufreeipa,dc=test 2025-05-07T18:02:07Z DEBUG updated dn: dc=ufreeipa,dc=test with {'objectclass': [b'top', b'domain', b'pilotObject']} 2025-05-07T18:02:07Z DEBUG updating dn: dc=ufreeipa,dc=test 2025-05-07T18:02:07Z DEBUG updated dn: dc=ufreeipa,dc=test with {'dc': [b'ufreeipa'], 'info': [b'IPA V2.0']} 2025-05-07T18:02:07Z DEBUG Created entry dc=ufreeipa,dc=test : {'objectclass': [b'top', b'domain', b'pilotObject'], 'dc': [b'ufreeipa'], 'info': [b'IPA V2.0']} 2025-05-07T18:02:07Z DEBUG completed creating DS instance 2025-05-07T18:02:07Z DEBUG step duration: dirsrv __create_instance 4.09 sec 2025-05-07T18:02:07Z DEBUG [2/45]: stopping directory server 2025-05-07T18:02:07Z DEBUG Starting external process 2025-05-07T18:02:07Z DEBUG args=['/bin/systemctl', 'stop', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:07Z DEBUG Process finished, return code=0 2025-05-07T18:02:07Z DEBUG stdout= 2025-05-07T18:02:07Z DEBUG stderr= 2025-05-07T18:02:07Z DEBUG Stop of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:02:07Z DEBUG step duration: dirsrv __stop_instance 0.33 sec 2025-05-07T18:02:07Z DEBUG [3/45]: updating configuration in dse.ldif 2025-05-07T18:02:07Z DEBUG Starting external process 2025-05-07T18:02:07Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:02:07Z DEBUG Process finished, return code=0 2025-05-07T18:02:07Z DEBUG stdout= 2025-05-07T18:02:07Z DEBUG stderr= 2025-05-07T18:02:07Z DEBUG Starting external process 2025-05-07T18:02:07Z DEBUG args=['/sbin/restorecon', '/etc/dirsrv/slapd-UFREEIPA-TEST/dse.ldif'] 2025-05-07T18:02:07Z DEBUG Process finished, return code=0 2025-05-07T18:02:07Z DEBUG stdout= 2025-05-07T18:02:07Z DEBUG stderr= 2025-05-07T18:02:07Z DEBUG step duration: dirsrv __update_dse_ldif 0.02 sec 2025-05-07T18:02:07Z DEBUG [4/45]: starting directory server 2025-05-07T18:02:07Z DEBUG Starting external process 2025-05-07T18:02:07Z DEBUG args=['/bin/systemctl', 'start', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:08Z DEBUG Process finished, return code=0 2025-05-07T18:02:08Z DEBUG stdout= 2025-05-07T18:02:08Z DEBUG stderr= 2025-05-07T18:02:08Z DEBUG Starting external process 2025-05-07T18:02:08Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:08Z DEBUG Process finished, return code=0 2025-05-07T18:02:08Z DEBUG stdout=active 2025-05-07T18:02:08Z DEBUG stderr= 2025-05-07T18:02:08Z DEBUG wait_for_open_ports: localhost [389] timeout 90 2025-05-07T18:02:08Z DEBUG waiting for port: 389 2025-05-07T18:02:08Z DEBUG SUCCESS: port: 389 2025-05-07T18:02:08Z DEBUG Start of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:02:08Z DEBUG Created connection context.ldap2_139937138938208 2025-05-07T18:02:08Z DEBUG step duration: dirsrv __start_instance 0.88 sec 2025-05-07T18:02:08Z DEBUG [5/45]: adding default schema 2025-05-07T18:02:08Z DEBUG step duration: dirsrv __add_default_schemas 0.00 sec 2025-05-07T18:02:08Z DEBUG [6/45]: enabling memberof plugin 2025-05-07T18:02:08Z DEBUG Starting external process 2025-05-07T18:02:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/memberof-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:08Z DEBUG Process finished, return code=0 2025-05-07T18:02:08Z DEBUG stdout=replace nsslapd-pluginenabled: on add memberofgroupattr: memberUser add memberofgroupattr: memberHost add memberofgroupattr: ipaOwner modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config" modify complete 2025-05-07T18:02:08Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:08Z DEBUG step duration: dirsrv __add_memberof_module 0.03 sec 2025-05-07T18:02:08Z DEBUG [7/45]: enabling winsync plugin 2025-05-07T18:02:08Z DEBUG Starting external process 2025-05-07T18:02:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-winsync-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:08Z DEBUG Process finished, return code=0 2025-05-07T18:02:08Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa-winsync add nsslapd-pluginpath: libipa_winsync add nsslapd-plugininitfunc: ipa_winsync_plugin_init add nsslapd-pluginDescription: Allows IPA to work with the DS windows sync feature add nsslapd-pluginid: ipa-winsync add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-plugin-depends-on-type: database add ipaWinSyncRealmFilter: (objectclass=krbRealmContainer) add ipaWinSyncRealmAttr: cn add ipaWinSyncNewEntryFilter: (cn=ipaConfig) add ipaWinSyncNewUserOCAttr: ipauserobjectclasses add ipaWinSyncUserFlatten: true add ipaWinsyncHomeDirAttr: ipaHomesRootDir add ipaWinsyncLoginShellAttr: ipaDefaultLoginShell add ipaWinSyncDefaultGroupAttr: ipaDefaultPrimaryGroup add ipaWinSyncDefaultGroupFilter: (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) add ipaWinSyncAcctDisable: both add ipaWinSyncForceSync: true add ipaWinSyncUserAttr: uidNumber -1 gidNumber -1 adding new entry "cn=ipa-winsync,cn=plugins,cn=config" modify complete 2025-05-07T18:02:08Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:08Z DEBUG step duration: dirsrv __add_winsync_module 0.28 sec 2025-05-07T18:02:08Z DEBUG [8/45]: configure password logging 2025-05-07T18:02:08Z DEBUG Starting external process 2025-05-07T18:02:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/pw-logging-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:09Z DEBUG Process finished, return code=0 2025-05-07T18:02:09Z DEBUG stdout=replace nsslapd-unhashed-pw-switch: nolog modifying entry "cn=config" modify complete 2025-05-07T18:02:09Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:09Z DEBUG step duration: dirsrv __password_logging 0.27 sec 2025-05-07T18:02:09Z DEBUG [9/45]: configuring replication version plugin 2025-05-07T18:02:09Z DEBUG Starting external process 2025-05-07T18:02:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpbgpuxe92', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:09Z DEBUG Process finished, return code=0 2025-05-07T18:02:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Version Replication add nsslapd-pluginpath: libipa_repl_version add nsslapd-plugininitfunc: repl_version_plugin_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: off add nsslapd-pluginid: ipa_repl_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Replication version plugin add nsslapd-plugin-depends-on-type: database add nsslapd-plugin-depends-on-named: Multisupplier Replication Plugin adding new entry "cn=IPA Version Replication,cn=plugins,cn=config" modify complete 2025-05-07T18:02:09Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:09Z DEBUG step duration: dirsrv __config_version_module 0.28 sec 2025-05-07T18:02:09Z DEBUG [10/45]: enabling IPA enrollment plugin 2025-05-07T18:02:09Z DEBUG Starting external process 2025-05-07T18:02:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp_p_7v6_t', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:09Z DEBUG Process finished, return code=0 2025-05-07T18:02:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_enrollment_extop add nsslapd-pluginpath: libipa_enrollment_extop add nsslapd-plugininitfunc: ipaenrollment_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_enrollment_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Enroll hosts into the IPA domain add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=ufreeipa,dc=test adding new entry "cn=ipa_enrollment_extop,cn=plugins,cn=config" modify complete 2025-05-07T18:02:09Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:09Z DEBUG step duration: dirsrv __add_enrollment_module 0.05 sec 2025-05-07T18:02:09Z DEBUG [11/45]: configuring uniqueness plugin 2025-05-07T18:02:09Z DEBUG Starting external process 2025-05-07T18:02:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpqa98kr_k', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:09Z DEBUG Process finished, return code=0 2025-05-07T18:02:09Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: krbPrincipalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbPrincipalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=ufreeipa,dc=test add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test add uniqueness-across-all-subtrees: on adding new entry "cn=krbPrincipalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: krbCanonicalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbCanonicalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=ufreeipa,dc=test add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test add uniqueness-across-all-subtrees: on adding new entry "cn=krbCanonicalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: netgroup uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=ng,cn=alt,dc=ufreeipa,dc=test add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values adding new entry "cn=netgroup uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: ipaUniqueID uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: ipaUniqueID add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=ufreeipa,dc=test add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test add uniqueness-across-all-subtrees: on adding new entry "cn=ipaUniqueID uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: sudorule name uniqueness add nsslapd-pluginDescription: Enforce unique attribute values add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=sudorules,cn=sudo,dc=ufreeipa,dc=test add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project adding new entry "cn=sudorule name uniqueness,cn=plugins,cn=config" modify complete 2025-05-07T18:02:09Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:09Z DEBUG step duration: dirsrv __set_unique_attrs 0.33 sec 2025-05-07T18:02:09Z DEBUG [12/45]: configuring uuid plugin 2025-05-07T18:02:09Z DEBUG Starting external process 2025-05-07T18:02:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/uuid-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:10Z DEBUG Process finished, return code=0 2025-05-07T18:02:10Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA UUID add nsslapd-pluginpath: libipa_uuid add nsslapd-plugininitfunc: ipauuid_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipauuid_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA UUID plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA UUID,cn=plugins,cn=config" modify complete 2025-05-07T18:02:10Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:10Z DEBUG Starting external process 2025-05-07T18:02:10Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpc1qeuvyc', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:10Z DEBUG Process finished, return code=0 2025-05-07T18:02:10Z DEBUG stdout=add objectclass: top extensibleObject add cn: IPA Unique IDs add ipaUuidAttr: ipaUniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (|(objectclass=ipaObject)(objectclass=ipaAssociation)) add ipaUuidScope: dc=ufreeipa,dc=test add ipaUuidEnforce: TRUE adding new entry "cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: IPK11 Unique IDs add ipaUuidAttr: ipk11UniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (objectclass=ipk11Object) add ipaUuidScope: dc=ufreeipa,dc=test add ipaUuidEnforce: FALSE adding new entry "cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete 2025-05-07T18:02:10Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:10Z DEBUG step duration: dirsrv __config_uuid_module 0.60 sec 2025-05-07T18:02:10Z DEBUG [13/45]: configuring modrdn plugin 2025-05-07T18:02:10Z DEBUG Starting external process 2025-05-07T18:02:10Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/modrdn-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:10Z DEBUG Process finished, return code=0 2025-05-07T18:02:10Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA MODRDN add nsslapd-pluginpath: libipa_modrdn add nsslapd-plugininitfunc: ipamodrdn_init add nsslapd-plugintype: betxnpostoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipamodrdn_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA MODRDN plugin add nsslapd-plugin-depends-on-type: database add nsslapd-pluginPrecedence: 60 adding new entry "cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2025-05-07T18:02:10Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:10Z DEBUG Starting external process 2025-05-07T18:02:10Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp1b_yh0g1', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:11Z DEBUG Process finished, return code=0 2025-05-07T18:02:11Z DEBUG stdout=add objectclass: top extensibleObject add cn: Kerberos Principal Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbPrincipalName add ipaModRDNsuffix: @UFREEIPA.TEST add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=ufreeipa,dc=test adding new entry "cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: Kerberos Canonical Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbCanonicalName add ipaModRDNsuffix: @UFREEIPA.TEST add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=ufreeipa,dc=test adding new entry "cn=Kerberos Canonical Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2025-05-07T18:02:11Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:11Z DEBUG step duration: dirsrv __config_modrdn_module 0.60 sec 2025-05-07T18:02:11Z DEBUG [14/45]: configuring DNS plugin 2025-05-07T18:02:11Z DEBUG Starting external process 2025-05-07T18:02:11Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-dns-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:11Z DEBUG Process finished, return code=0 2025-05-07T18:02:11Z DEBUG stdout=add objectclass: top nsslapdPlugin extensibleObject add cn: IPA DNS add nsslapd-plugindescription: IPA DNS support plugin add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_dns add nsslapd-plugininitfunc: ipadns_init add nsslapd-pluginpath: libipa_dns.so add nsslapd-plugintype: preoperation add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-pluginversion: 1.0 add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA DNS,cn=plugins,cn=config" modify complete 2025-05-07T18:02:11Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:11Z DEBUG step duration: dirsrv __config_dns_module 0.04 sec 2025-05-07T18:02:11Z DEBUG [15/45]: enabling entryUSN plugin 2025-05-07T18:02:11Z DEBUG Starting external process 2025-05-07T18:02:11Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/entryusn.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:11Z DEBUG Process finished, return code=0 2025-05-07T18:02:11Z DEBUG stdout=replace nsslapd-entryusn-global: on modifying entry "cn=config" modify complete replace nsslapd-entryusn-import-initval: next modifying entry "cn=config" modify complete replace nsslapd-pluginenabled: on modifying entry "cn=USN,cn=plugins,cn=config" modify complete 2025-05-07T18:02:11Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:11Z DEBUG step duration: dirsrv __enable_entryusn 0.05 sec 2025-05-07T18:02:11Z DEBUG [16/45]: configuring lockout plugin 2025-05-07T18:02:11Z DEBUG Starting external process 2025-05-07T18:02:11Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/lockout-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:11Z DEBUG Process finished, return code=0 2025-05-07T18:02:11Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Lockout add nsslapd-pluginpath: libipa_lockout add nsslapd-plugininitfunc: ipalockout_init add nsslapd-plugintype: object add nsslapd-pluginenabled: on add nsslapd-pluginid: ipalockout_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Lockout plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA Lockout,cn=plugins,cn=config" modify complete 2025-05-07T18:02:11Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:11Z DEBUG step duration: dirsrv __config_lockout_module 0.03 sec 2025-05-07T18:02:11Z DEBUG [17/45]: configuring graceperiod plugin 2025-05-07T18:02:11Z DEBUG Starting external process 2025-05-07T18:02:11Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/graceperiod-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:11Z DEBUG Process finished, return code=0 2025-05-07T18:02:11Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Graceperiod add nsslapd-pluginpath: libipa_graceperiod add nsslapd-plugininitfunc: ipagraceperiod_init add nsslapd-plugintype: object add nsslapd-pluginenabled: on add nsslapd-pluginid: ipagraceperiod_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Graceperiod plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA Graceperiod,cn=plugins,cn=config" modify complete 2025-05-07T18:02:11Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:11Z DEBUG step duration: dirsrv config_graceperiod_module 0.28 sec 2025-05-07T18:02:11Z DEBUG [18/45]: configuring topology plugin 2025-05-07T18:02:11Z DEBUG Starting external process 2025-05-07T18:02:11Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpa07thr0z', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:11Z DEBUG Process finished, return code=0 2025-05-07T18:02:11Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: IPA Topology Configuration add nsslapd-pluginPath: libtopology add nsslapd-pluginInitfunc: ipa_topo_init add nsslapd-pluginType: object add nsslapd-pluginEnabled: on add nsslapd-topo-plugin-shared-config-base: cn=ipa,cn=etc,dc=ufreeipa,dc=test add nsslapd-topo-plugin-shared-replica-root: dc=ufreeipa,dc=test o=ipaca add nsslapd-topo-plugin-shared-binddngroup: cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test add nsslapd-topo-plugin-startup-delay: 20 add nsslapd-pluginId: none add nsslapd-plugin-depends-on-named: ldbm database Multisupplier Replication Plugin add nsslapd-pluginVersion: 1.0 add nsslapd-pluginVendor: none add nsslapd-pluginDescription: none adding new entry "cn=IPA Topology Configuration,cn=plugins,cn=config" modify complete 2025-05-07T18:02:11Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:11Z DEBUG step duration: dirsrv __config_topology_module 0.27 sec 2025-05-07T18:02:11Z DEBUG [19/45]: creating indices 2025-05-07T18:02:11Z DEBUG importing all plugin modules in ipaserver.plugins... 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.aci 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.automember 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.automount 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.baseldap 2025-05-07T18:02:11Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.baseuser 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.batch 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.ca 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.caacl 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.cert 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.certmap 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.certprofile 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.config 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.delegation 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.dns 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.dogtag 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.group 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.hbac 2025-05-07T18:02:11Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.hbactest 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.host 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.idp 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.idrange 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.idviews 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.internal 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.join 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.ldap2 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.location 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.migration 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.misc 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.netgroup 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.otp 2025-05-07T18:02:11Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.otptoken 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.passkeyconfig 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.passwd 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.permission 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.ping 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.pkinit 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.privilege 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.rabase 2025-05-07T18:02:11Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.role 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.schema 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.selfservice 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.server 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.serverrole 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.serverroles 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.service 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.session 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.stageuser 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.subid 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.sudo 2025-05-07T18:02:11Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.sudorule 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.topology 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.trust 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.user 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.vault 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.virtual 2025-05-07T18:02:11Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.whoami 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2025-05-07T18:02:11Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.dns 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_subid_support 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2025-05-07T18:02:11Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2025-05-07T18:02:12Z DEBUG Created connection context.ldap2_139937128667792 2025-05-07T18:02:12Z DEBUG raw: idrange_show('UFREEIPA.TEST_id_range', version='2.254') 2025-05-07T18:02:12Z DEBUG idrange_show('UFREEIPA.TEST_id_range', rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:02:12Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:02:12Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:02:12Z DEBUG Parsing update file '/usr/share/ipa/updates/20-indices.update' 2025-05-07T18:02:12Z DEBUG New entry: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'accessRuleType', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['accessRuleType'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG accessRuleType 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'altSecurityIdentities', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['altSecurityIdentities'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG altSecurityIdentities 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'automountkey', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['automountkey'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG automountkey 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG pres 2025-05-07T18:02:12Z DEBUG New entry: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'automountMapName', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['automountMapName'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG automountMapName 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'carLicense', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['carLicense'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG carLicense 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG sub 2025-05-07T18:02:12Z DEBUG New entry: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsindex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'description', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['description'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsindex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG description 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG sub 2025-05-07T18:02:12Z DEBUG New entry: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'displayname', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['displayname'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG displayname 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG sub 2025-05-07T18:02:12Z DEBUG New entry: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'fqdn', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['fqdn'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:12Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG fqdn 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG pres 2025-05-07T18:02:12Z DEBUG sub 2025-05-07T18:02:12Z DEBUG Updating existing entry: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG gidnumber 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG only: set cn to 'gidnumber', current value ['gidnumber'] 2025-05-07T18:02:12Z DEBUG only: updated value ['gidnumber'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG gidnumber 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG nsMatchingRule: 2025-05-07T18:02:12Z DEBUG integerOrderingMatch 2025-05-07T18:02:12Z DEBUG [(2, 'nsMatchingRule', ['integerOrderingMatch'])] 2025-05-07T18:02:12Z DEBUG Updated 1 2025-05-07T18:02:12Z DEBUG update_entry modlist [(2, 'nsMatchingRule', [b'integerOrderingMatch'])] 2025-05-07T18:02:12Z DEBUG Done 2025-05-07T18:02:12Z DEBUG New entry: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'hostCategory', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['hostCategory'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG hostCategory 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'idnsName', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['idnsName'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG idnsName 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaallowedtarget', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaallowedtarget'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:12Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaallowedtarget 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG pres 2025-05-07T18:02:12Z DEBUG sub 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaAnchorUUID', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaAnchorUUID'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaAnchorUUID 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG pres 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaassignedidview', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaassignedidview'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:12Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaassignedidview 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG pres 2025-05-07T18:02:12Z DEBUG sub 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaCASubjectDN', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaCASubjectDN'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaCASubjectDN 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaCertmapData', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaCertmapData'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaCertmapData 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaConfigString', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaConfigString'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaConfigString 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaEnabledFlag', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaEnabledFlag'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaEnabledFlag 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaExternalMember', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaExternalMember'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaExternalMember 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaIdpDevAuthEndpoint', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaIdpDevAuthEndpoint'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaIdpDevAuthEndpoint 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG sub 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaIdpAuthEndpoint', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaIdpAuthEndpoint'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaIdpAuthEndpoint 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG sub 2025-05-07T18:02:12Z DEBUG New entry: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Initial value 2025-05-07T18:02:12Z DEBUG dn: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG only: set cn to 'ipaIdpScope', current value [] 2025-05-07T18:02:12Z DEBUG only: updated value ['ipaIdpScope'] 2025-05-07T18:02:12Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:12Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:12Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:12Z DEBUG --------------------------------------------- 2025-05-07T18:02:12Z DEBUG Final value after applying updates 2025-05-07T18:02:12Z DEBUG dn: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:12Z DEBUG objectClass: 2025-05-07T18:02:12Z DEBUG nsIndex 2025-05-07T18:02:12Z DEBUG top 2025-05-07T18:02:12Z DEBUG nsSystemIndex: 2025-05-07T18:02:12Z DEBUG false 2025-05-07T18:02:12Z DEBUG cn: 2025-05-07T18:02:12Z DEBUG ipaIdpScope 2025-05-07T18:02:12Z DEBUG nsIndexType: 2025-05-07T18:02:12Z DEBUG eq 2025-05-07T18:02:12Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaIdpTokenEndpoint', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaIdpTokenEndpoint'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaIdpTokenEndpoint 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaKrbAuthzData', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaKrbAuthzData'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaKrbAuthzData 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipakrbprincipalalias', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipakrbprincipalalias'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipakrbprincipalalias 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG New entry: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipalocation', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipalocation'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipalocation 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaMemberCa', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaMemberCa'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaMemberCa 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaMemberCertProfile', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaMemberCertProfile'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaMemberCertProfile 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaNTSecurityIdentifier', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaNTSecurityIdentifier'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaNTSecurityIdentifier 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaNTTrustPartner', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaNTTrustPartner'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['pres'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaNTTrustPartner 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaOriginalUid', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaOriginalUid'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaOriginalUid 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaOwner', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaOwner'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaOwner 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG New entry: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipasudorunas', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipasudorunas'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipasudorunas 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaSubGidNumber', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaSubGidNumber'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaSubGidNumber 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG nsMatchingRule: 2025-05-07T18:02:13Z DEBUG integerOrderingMatch 2025-05-07T18:02:13Z DEBUG New entry: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipaSubUidNumber', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipaSubUidNumber'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipaSubUidNumber 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG nsMatchingRule: 2025-05-07T18:02:13Z DEBUG integerOrderingMatch 2025-05-07T18:02:13Z DEBUG New entry: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'sudoorder', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['sudoorder'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG sudoorder 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG nsMatchingRule: 2025-05-07T18:02:13Z DEBUG integerOrderingMatch 2025-05-07T18:02:13Z DEBUG New entry: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipasudorunasgroup', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipasudorunasgroup'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipasudorunasgroup 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipatokenradiusconfiglink', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipatokenradiusconfiglink'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipatokenradiusconfiglink 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipauniqueid', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipauniqueid'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipauniqueid 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG New entry: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'ipServicePort', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['ipServicePort'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG ipServicePort 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG New entry: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'krbCanonicalName', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['krbCanonicalName'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG krbCanonicalName 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'krbPasswordExpiration', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['krbPasswordExpiration'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG krbPasswordExpiration 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG New entry: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'krbPrincipalName', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['krbPrincipalName'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:13Z DEBUG add: 'caseIgnoreIA5Match' to nsMatchingRule, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['caseIgnoreIA5Match'] 2025-05-07T18:02:13Z DEBUG add: 'caseExactIA5Match' to nsMatchingRule, current value ['caseIgnoreIA5Match'] 2025-05-07T18:02:13Z DEBUG add: updated value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG krbPrincipalName 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG nsMatchingRule: 2025-05-07T18:02:13Z DEBUG caseIgnoreIA5Match 2025-05-07T18:02:13Z DEBUG caseExactIA5Match 2025-05-07T18:02:13Z DEBUG New entry: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsindex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'l', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['l'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsindex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG l 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'macAddress', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['macAddress'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG macAddress 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG New entry: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'managedby', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['managedby'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG managedby 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'manager', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['manager'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG manager 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG Updating existing entry: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG member 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG only: set cn to 'member', current value ['member'] 2025-05-07T18:02:13Z DEBUG only: updated value ['member'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG member 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG [(0, 'nsIndexType', ['pres', 'sub'])] 2025-05-07T18:02:13Z DEBUG Updated 1 2025-05-07T18:02:13Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'pres', b'sub'])] 2025-05-07T18:02:13Z DEBUG Done 2025-05-07T18:02:13Z DEBUG New entry: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'memberallowcmd', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['memberallowcmd'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberallowcmd 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'memberdenycmd', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['memberdenycmd'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberdenycmd 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'memberHost', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['memberHost'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberHost 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'memberManager', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['memberManager'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberManager 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG Updating existing entry: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberOf 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG only: set cn to 'memberOf', current value ['memberOf'] 2025-05-07T18:02:13Z DEBUG only: updated value ['memberOf'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberOf 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG [(0, 'nsIndexType', ['sub'])] 2025-05-07T18:02:13Z DEBUG Updated 1 2025-05-07T18:02:13Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'sub'])] 2025-05-07T18:02:13Z DEBUG Done 2025-05-07T18:02:13Z DEBUG New entry: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'memberPrincipal', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['memberPrincipal'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberPrincipal 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG New entry: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'memberservice', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['memberservice'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberservice 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG Updating existing entry: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberuid 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG only: set cn to 'memberuid', current value ['memberuid'] 2025-05-07T18:02:13Z DEBUG only: updated value ['memberuid'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberuid 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG [(0, 'nsIndexType', ['pres'])] 2025-05-07T18:02:13Z DEBUG Updated 1 2025-05-07T18:02:13Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'pres'])] 2025-05-07T18:02:13Z DEBUG Done 2025-05-07T18:02:13Z DEBUG New entry: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'memberUser', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['memberUser'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsIndex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG memberUser 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG pres 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsindex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'nsHardwarePlatform', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['nsHardwarePlatform'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsindex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG nsHardwarePlatform 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsindex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'nsHostLocation', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['nsHostLocation'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsindex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG nsHostLocation 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:13Z DEBUG New entry: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Initial value 2025-05-07T18:02:13Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsindex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG only: set cn to 'nsOsVersion', current value [] 2025-05-07T18:02:13Z DEBUG only: updated value ['nsOsVersion'] 2025-05-07T18:02:13Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:13Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:13Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:13Z DEBUG --------------------------------------------- 2025-05-07T18:02:13Z DEBUG Final value after applying updates 2025-05-07T18:02:13Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:13Z DEBUG objectClass: 2025-05-07T18:02:13Z DEBUG nsindex 2025-05-07T18:02:13Z DEBUG top 2025-05-07T18:02:13Z DEBUG nsSystemIndex: 2025-05-07T18:02:13Z DEBUG false 2025-05-07T18:02:13Z DEBUG cn: 2025-05-07T18:02:13Z DEBUG nsOsVersion 2025-05-07T18:02:13Z DEBUG nsIndexType: 2025-05-07T18:02:13Z DEBUG eq 2025-05-07T18:02:13Z DEBUG sub 2025-05-07T18:02:14Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG ntUniqueId 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG only: set cn to 'ntUniqueId', current value ['ntUniqueId'] 2025-05-07T18:02:14Z DEBUG only: updated value ['ntUniqueId'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG ntUniqueId 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG pres 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG [(0, 'nsIndexType', ['pres'])] 2025-05-07T18:02:14Z DEBUG Updated 1 2025-05-07T18:02:14Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'pres'])] 2025-05-07T18:02:14Z DEBUG Done 2025-05-07T18:02:14Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG ntUserDomainId 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG only: set cn to 'ntUserDomainId', current value ['ntUserDomainId'] 2025-05-07T18:02:14Z DEBUG only: updated value ['ntUserDomainId'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG ntUserDomainId 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG pres 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG [(0, 'nsIndexType', ['pres'])] 2025-05-07T18:02:14Z DEBUG Updated 1 2025-05-07T18:02:14Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'pres'])] 2025-05-07T18:02:14Z DEBUG Done 2025-05-07T18:02:14Z DEBUG New entry: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG only: set cn to 'ou', current value [] 2025-05-07T18:02:14Z DEBUG only: updated value ['ou'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG ou 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG sub 2025-05-07T18:02:14Z DEBUG Updating existing entry: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG owner 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG only: set cn to 'owner', current value ['owner'] 2025-05-07T18:02:14Z DEBUG only: updated value ['owner'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG owner 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG sub 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG [(0, 'nsIndexType', ['sub'])] 2025-05-07T18:02:14Z DEBUG Updated 1 2025-05-07T18:02:14Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'sub'])] 2025-05-07T18:02:14Z DEBUG Done 2025-05-07T18:02:14Z DEBUG New entry: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG only: set cn to 'secretary', current value [] 2025-05-07T18:02:14Z DEBUG only: updated value ['secretary'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:14Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG secretary 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG pres 2025-05-07T18:02:14Z DEBUG sub 2025-05-07T18:02:14Z DEBUG Updating existing entry: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG seeAlso 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG only: set cn to 'seealso', current value ['seeAlso'] 2025-05-07T18:02:14Z DEBUG only: updated value ['seealso'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG seealso 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG sub 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG [(0, 'nsIndexType', ['sub']), (1, 'cn', ['seeAlso']), (0, 'cn', ['seealso'])] 2025-05-07T18:02:14Z DEBUG Updated 1 2025-05-07T18:02:14Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'sub']), (1, 'cn', [b'seeAlso']), (0, 'cn', [b'seealso'])] 2025-05-07T18:02:14Z DEBUG Done 2025-05-07T18:02:14Z DEBUG New entry: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG only: set cn to 'serverhostname', current value [] 2025-05-07T18:02:14Z DEBUG only: updated value ['serverhostname'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG serverhostname 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG sub 2025-05-07T18:02:14Z DEBUG New entry: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG only: set cn to 'sourcehost', current value [] 2025-05-07T18:02:14Z DEBUG only: updated value ['sourcehost'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:14Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG sourcehost 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG pres 2025-05-07T18:02:14Z DEBUG sub 2025-05-07T18:02:14Z DEBUG New entry: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG only: set cn to 'title', current value [] 2025-05-07T18:02:14Z DEBUG only: updated value ['title'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG title 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG sub 2025-05-07T18:02:14Z DEBUG Updating existing entry: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG uid 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG only: set cn to 'uid', current value ['uid'] 2025-05-07T18:02:14Z DEBUG only: updated value ['uid'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG uid 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG sub 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG [(0, 'nsIndexType', ['sub'])] 2025-05-07T18:02:14Z DEBUG Updated 1 2025-05-07T18:02:14Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'sub'])] 2025-05-07T18:02:14Z DEBUG Done 2025-05-07T18:02:14Z DEBUG Updating existing entry: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG uidnumber 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG only: set cn to 'uidnumber', current value ['uidnumber'] 2025-05-07T18:02:14Z DEBUG only: updated value ['uidnumber'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2025-05-07T18:02:14Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG uidnumber 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG nsMatchingRule: 2025-05-07T18:02:14Z DEBUG integerOrderingMatch 2025-05-07T18:02:14Z DEBUG [(2, 'nsMatchingRule', ['integerOrderingMatch'])] 2025-05-07T18:02:14Z DEBUG Updated 1 2025-05-07T18:02:14Z DEBUG update_entry modlist [(2, 'nsMatchingRule', [b'integerOrderingMatch'])] 2025-05-07T18:02:14Z DEBUG Done 2025-05-07T18:02:14Z DEBUG Updating existing entry: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG uniquemember 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG only: set cn to 'uniquemember', current value ['uniquemember'] 2025-05-07T18:02:14Z DEBUG only: updated value ['uniquemember'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG uniquemember 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG sub 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG [(0, 'nsIndexType', ['sub'])] 2025-05-07T18:02:14Z DEBUG Updated 1 2025-05-07T18:02:14Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'sub'])] 2025-05-07T18:02:14Z DEBUG Done 2025-05-07T18:02:14Z DEBUG New entry: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Initial value 2025-05-07T18:02:14Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG only: set cn to 'userCertificate', current value [] 2025-05-07T18:02:14Z DEBUG only: updated value ['userCertificate'] 2025-05-07T18:02:14Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq'] 2025-05-07T18:02:14Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:02:14Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:02:14Z DEBUG --------------------------------------------- 2025-05-07T18:02:14Z DEBUG Final value after applying updates 2025-05-07T18:02:14Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:02:14Z DEBUG objectClass: 2025-05-07T18:02:14Z DEBUG nsIndex 2025-05-07T18:02:14Z DEBUG top 2025-05-07T18:02:14Z DEBUG nsSystemIndex: 2025-05-07T18:02:14Z DEBUG false 2025-05-07T18:02:14Z DEBUG cn: 2025-05-07T18:02:14Z DEBUG userCertificate 2025-05-07T18:02:14Z DEBUG nsIndexType: 2025-05-07T18:02:14Z DEBUG eq 2025-05-07T18:02:14Z DEBUG pres 2025-05-07T18:02:14Z DEBUG Creating task cn=indextask_139659337343344040_15571,cn=index,cn=tasks,cn=config to index attributes: accessRuleType, altSecurityIdentities, automountMapName, automountkey, carLicense, description, displayname, fqdn, gidnumber, hostCategory, idnsName, ipServicePort, ipaAnchorUUID, ipaCASubjectDN, ipaCertmapData, ipaConfigString, ipaEnabledFlag, ipaExternalMember, ipaIdpAuthEndpoint, ipaIdpDevAuthEndpoint, ipaIdpScope, ipaIdpTokenEndpoint, ipaKrbAuthzData, ipaMemberCa, ipaMemberCertProfile, ipaNTSecurityIdentifier, ipaNTTrustPartner, ipaOriginalUid, ipaOwner, ipaSubGidNumber, ipaSubUidNumber, ipaallowedtarget, ipaassignedidview, ipakrbprincipalalias, ipalocation, ipasudorunas, ipasudorunasgroup, ipatokenradiusconfiglink, ipauniqueid, krbCanonicalName, krbPasswordExpiration, krbPrincipalName, l, macAddress, managedby, manager, member, memberHost, memberManager, memberOf, memberPrincipal, memberUser, memberallowcmd, memberdenycmd, memberservice, memberuid, nsHardwarePlatform, nsHostLocation, nsOsVersion, ntUniqueId, ntUserDomainId, ou, owner, secretary, seealso, serverhostname, sourcehost, sudoorder, title, uid, uidnumber, uniquemember, userCertificate 2025-05-07T18:02:16Z DEBUG Indexing finished 2025-05-07T18:02:16Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-indices.update 3.959 sec 2025-05-07T18:02:16Z DEBUG Destroyed connection context.ldap2_139937128667792 2025-05-07T18:02:16Z DEBUG step duration: dirsrv __create_indices 4.66 sec 2025-05-07T18:02:16Z DEBUG [20/45]: enabling referential integrity plugin 2025-05-07T18:02:16Z DEBUG Starting external process 2025-05-07T18:02:16Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/referint-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:16Z DEBUG Process finished, return code=0 2025-05-07T18:02:16Z DEBUG stdout=replace nsslapd-pluginenabled: on modifying entry "cn=referential integrity postoperation,cn=plugins,cn=config" modify complete 2025-05-07T18:02:16Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:16Z DEBUG step duration: dirsrv __add_referint_module 0.31 sec 2025-05-07T18:02:16Z DEBUG [21/45]: configuring certmap.conf 2025-05-07T18:02:16Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:02:16Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:02:16Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:02:16Z DEBUG step duration: dirsrv __certmap_conf 0.00 sec 2025-05-07T18:02:16Z DEBUG [22/45]: configure new location for managed entries 2025-05-07T18:02:16Z DEBUG Starting external process 2025-05-07T18:02:16Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp2_957hsi', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:16Z DEBUG Process finished, return code=0 2025-05-07T18:02:16Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test modifying entry "cn=Managed Entries,cn=plugins,cn=config" modify complete 2025-05-07T18:02:16Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:16Z DEBUG step duration: dirsrv __repoint_managed_entries 0.04 sec 2025-05-07T18:02:16Z DEBUG [23/45]: configure dirsrv ccache and keytab 2025-05-07T18:02:16Z DEBUG Starting external process 2025-05-07T18:02:16Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:02:16Z DEBUG Process finished, return code=0 2025-05-07T18:02:16Z DEBUG stdout= 2025-05-07T18:02:16Z DEBUG stderr= 2025-05-07T18:02:16Z DEBUG Starting external process 2025-05-07T18:02:16Z DEBUG args=['/sbin/restorecon', '/etc/systemd/system/dirsrv@UFREEIPA-TEST.service.d/ipa-env.conf'] 2025-05-07T18:02:16Z DEBUG Process finished, return code=0 2025-05-07T18:02:16Z DEBUG stdout= 2025-05-07T18:02:16Z DEBUG stderr= 2025-05-07T18:02:16Z DEBUG Starting external process 2025-05-07T18:02:16Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2025-05-07T18:02:17Z DEBUG Process finished, return code=0 2025-05-07T18:02:17Z DEBUG stdout= 2025-05-07T18:02:17Z DEBUG stderr= 2025-05-07T18:02:17Z DEBUG step duration: dirsrv configure_systemd_ipa_env 0.35 sec 2025-05-07T18:02:17Z DEBUG [24/45]: enabling SASL mapping fallback 2025-05-07T18:02:17Z DEBUG Starting external process 2025-05-07T18:02:17Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpxzj7ch2z', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:17Z DEBUG Process finished, return code=0 2025-05-07T18:02:17Z DEBUG stdout=replace nsslapd-sasl-mapping-fallback: on modifying entry "cn=config" modify complete 2025-05-07T18:02:17Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:17Z DEBUG step duration: dirsrv __enable_sasl_mapping_fallback 0.03 sec 2025-05-07T18:02:17Z DEBUG [25/45]: restarting directory server 2025-05-07T18:02:17Z DEBUG Destroyed connection context.ldap2_139937138938208 2025-05-07T18:02:17Z DEBUG Starting external process 2025-05-07T18:02:17Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2025-05-07T18:02:17Z DEBUG Process finished, return code=0 2025-05-07T18:02:17Z DEBUG stdout= 2025-05-07T18:02:17Z DEBUG stderr= 2025-05-07T18:02:17Z DEBUG Starting external process 2025-05-07T18:02:17Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:18Z DEBUG Process finished, return code=0 2025-05-07T18:02:18Z DEBUG stdout= 2025-05-07T18:02:18Z DEBUG stderr= 2025-05-07T18:02:18Z DEBUG Starting external process 2025-05-07T18:02:18Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:18Z DEBUG Process finished, return code=0 2025-05-07T18:02:18Z DEBUG stdout=active 2025-05-07T18:02:18Z DEBUG stderr= 2025-05-07T18:02:18Z DEBUG wait_for_open_ports: localhost [389] timeout 90 2025-05-07T18:02:18Z DEBUG waiting for port: 389 2025-05-07T18:02:18Z DEBUG SUCCESS: port: 389 2025-05-07T18:02:18Z DEBUG Restart of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:02:18Z DEBUG Starting external process 2025-05-07T18:02:18Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:18Z DEBUG Process finished, return code=0 2025-05-07T18:02:18Z DEBUG stdout=active 2025-05-07T18:02:18Z DEBUG stderr= 2025-05-07T18:02:18Z DEBUG Created connection context.ldap2_139937138938208 2025-05-07T18:02:18Z DEBUG step duration: dirsrv __restart_instance 1.63 sec 2025-05-07T18:02:18Z DEBUG [26/45]: adding sasl mappings to the directory 2025-05-07T18:02:19Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:02:19Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:02:19Z DEBUG step duration: dirsrv __configure_sasl_mappings 0.45 sec 2025-05-07T18:02:19Z DEBUG [27/45]: adding default layout 2025-05-07T18:02:19Z DEBUG Starting external process 2025-05-07T18:02:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpj0420v9f', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:20Z DEBUG Process finished, return code=0 2025-05-07T18:02:20Z DEBUG stdout=add objectClass: top nsContainer add cn: accounts adding new entry "cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: users adding new entry "cn=users,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: groups adding new entry "cn=groups,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: services adding new entry "cn=services,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: computers adding new entry "cn=computers,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: hostgroups adding new entry "cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: ipservices adding new entry "cn=ipservices,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer add cn: alt adding new entry "cn=alt,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer add cn: ng adding new entry "cn=ng,cn=alt,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer add cn: automount adding new entry "cn=automount,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer add cn: default adding new entry "cn=default,cn=automount,dc=ufreeipa,dc=test" modify complete add objectClass: automountMap add automountMapName: auto.master adding new entry "automountmapname=auto.master,cn=default,cn=automount,dc=ufreeipa,dc=test" modify complete add objectClass: automountMap add automountMapName: auto.direct adding new entry "automountmapname=auto.direct,cn=default,cn=automount,dc=ufreeipa,dc=test" modify complete add objectClass: automount add automountKey: /- add automountInformation: auto.direct add description: /- auto.direct adding new entry "description=/- auto.direct,automountmapname=auto.master,cn=default,cn=automount,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: hbac adding new entry "cn=hbac,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: hbacservices adding new entry "cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: hbacservicegroups adding new entry "cn=hbacservicegroups,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: sudo adding new entry "cn=sudo,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: sudocmds adding new entry "cn=sudocmds,cn=sudo,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: sudocmdgroups adding new entry "cn=sudocmdgroups,cn=sudo,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: sudorules adding new entry "cn=sudorules,cn=sudo,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: etc adding new entry "cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: locations adding new entry "cn=locations,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: sysaccounts adding new entry "cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: ipa adding new entry "cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: masters adding new entry "cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: replicas adding new entry "cn=replicas,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: dna adding new entry "cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: posix-ids adding new entry "cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: subordinate-ids adding new entry "cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: ca_renewal adding new entry "cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: certificates adding new entry "cn=certificates,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: custodia adding new entry "cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: dogtag adding new entry "cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: s4u2proxy adding new entry "cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: ipaKrb5DelegationACL groupOfPrincipals top add cn: ipa-http-delegation add memberPrincipal: HTTP/master.ufreeipa.test@UFREEIPA.TEST add ipaAllowedTarget: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test adding new entry "cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: groupOfPrincipals top add cn: ipa-ldap-delegation-targets add memberPrincipal: ldap/master.ufreeipa.test@UFREEIPA.TEST adding new entry "cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: groupOfPrincipals top add cn: ipa-cifs-delegation-targets adding new entry "cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: top person posixaccount krbprincipalaux krbticketpolicyaux inetuser ipaobject ipasshuser add uid: admin add krbPrincipalName: admin@UFREEIPA.TEST root@UFREEIPA.TEST add cn: Administrator add sn: Administrator add uidNumber: 63800000 add gidNumber: 63800000 add homeDirectory: /home/admin add loginShell: /bin/bash add gecos: Administrator add nsAccountLock: FALSE add ipaUniqueID: autogenerate adding new entry "uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames posixgroup ipausergroup ipaobject add cn: admins add description: Account administrators group add gidNumber: 63800000 add member: uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test add nsAccountLock: FALSE add ipaUniqueID: autogenerate adding new entry "cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup ipausergroup ipaobject add description: Default group for all users add cn: ipausers add ipaUniqueID: autogenerate adding new entry "cn=ipausers,cn=groups,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames posixgroup ipausergroup ipaobject add gidNumber: 63800002 add description: Limited admins who can edit other users add cn: editors add ipaUniqueID: autogenerate adding new entry "cn=editors,cn=groups,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top groupOfNames nestedGroup ipaobject ipahostgroup add description: IPA server hosts add cn: ipaservers add ipaUniqueID: autogenerate adding new entry "cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: sshd add description: sshd add ipauniqueid: autogenerate adding new entry "cn=sshd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: ftp add description: ftp add ipauniqueid: autogenerate adding new entry "cn=ftp,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: su add description: su add ipauniqueid: autogenerate adding new entry "cn=su,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: login add description: login add ipauniqueid: autogenerate adding new entry "cn=login,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: su-l add description: su with login shell add ipauniqueid: autogenerate adding new entry "cn=su-l,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: sudo add description: sudo add ipauniqueid: autogenerate adding new entry "cn=sudo,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: sudo-i add description: sudo-i add ipauniqueid: autogenerate adding new entry "cn=sudo-i,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: systemd-user add description: pam_systemd and systemd user@.service add ipauniqueid: autogenerate adding new entry "cn=systemd-user,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: gdm add description: gdm add ipauniqueid: autogenerate adding new entry "cn=gdm,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: gdm-password add description: gdm-password add ipauniqueid: autogenerate adding new entry "cn=gdm-password,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipahbacservice ipaobject add cn: kdm add description: kdm add ipauniqueid: autogenerate adding new entry "cn=kdm,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectClass: ipaobject ipahbacservicegroup nestedGroup groupOfNames top add cn: Sudo add ipauniqueid: autogenerate add description: Default group of Sudo related services add member: cn=sudo,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test cn=sudo-i,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test adding new entry "cn=Sudo,cn=hbacservicegroups,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top ipaGuiConfig ipaConfigObject add ipaUserSearchFields: uid,givenname,sn,telephonenumber,ou,title add ipaGroupSearchFields: cn,description add ipaSearchTimeLimit: 2 add ipaSearchRecordsLimit: 100 add ipaHomesRootDir: /home add ipaDefaultLoginShell: /bin/sh add ipaDefaultPrimaryGroup: ipausers add ipaMaxUsernameLength: 32 add ipaMaxHostnameLength: 64 add ipaPwdExpAdvNotify: 4 add ipaGroupObjectClasses: top groupofnames nestedgroup ipausergroup ipaobject add ipaUserObjectClasses: top person organizationalperson inetorgperson inetuser posixaccount krbprincipalaux krbticketpolicyaux ipaobject ipasshuser add ipaDefaultEmailDomain: ufreeipa.test add ipaMigrationEnabled: FALSE add ipaConfigString: AllowNThash KDC:Disable Last Success add ipaSELinuxUserMapOrder: guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 add ipaSELinuxUserMapDefault: unconfined_u:s0-s0:c0.c1023 adding new entry "cn=ipaConfig,cn=etc,dc=ufreeipa,dc=test" modify complete add objectclass: top nsContainer add cn: cosTemplates adding new entry "cn=cosTemplates,cn=accounts,dc=ufreeipa,dc=test" modify complete add description: Password Policy based on group membership add objectClass: top ldapsubentry cosSuperDefinition cosClassicDefinition add cosTemplateDn: cn=cosTemplates,cn=accounts,dc=ufreeipa,dc=test add cosAttribute: krbPwdPolicyReference override add cosSpecifier: memberOf adding new entry "cn=Password Policy,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: selinux adding new entry "cn=selinux,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: usermap adding new entry "cn=usermap,cn=selinux,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: ranges adding new entry "cn=ranges,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: top ipaIDrange ipaDomainIDRange add cn: UFREEIPA.TEST_id_range add ipaBaseID: 63800000 add ipaIDRangeSize: 200000 add ipaRangeType: ipa-local adding new entry "cn=UFREEIPA.TEST_id_range,cn=ranges,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: top ipaIDrange ipaTrustedADDomainRange add cn: UFREEIPA.TEST_subid_range add ipaBaseID: 2147483648 add ipaIDRangeSize: 2147352576 add ipaBaseRID: 2147283648 add ipaNTTrustedDomainSID: S-1-5-21-738065-838566-412112059 add ipaRangeType: ipa-ad-trust adding new entry "cn=UFREEIPA.TEST_subid_range,cn=ranges,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: ca adding new entry "cn=ca,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: certprofiles adding new entry "cn=certprofiles,cn=ca,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: caacls adding new entry "cn=caacls,cn=ca,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: cas adding new entry "cn=cas,cn=ca,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:20Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:20Z DEBUG step duration: dirsrv __add_default_layout 1.50 sec 2025-05-07T18:02:20Z DEBUG [28/45]: adding delegation layout 2025-05-07T18:02:20Z DEBUG Starting external process 2025-05-07T18:02:20Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmplyfq0hx3', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:21Z DEBUG Process finished, return code=0 2025-05-07T18:02:21Z DEBUG stdout=add objectClass: top nsContainer add cn: roles adding new entry "cn=roles,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: pbac adding new entry "cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: privileges adding new entry "cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: permissions adding new entry "cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: helpdesk add description: Helpdesk adding new entry "cn=helpdesk,cn=roles,cn=accounts,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: User Administrators add description: User Administrators adding new entry "cn=User Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Group Administrators add description: Group Administrators adding new entry "cn=Group Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Administrators add description: Host Administrators adding new entry "cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Group Administrators add description: Host Group Administrators adding new entry "cn=Host Group Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Delegation Administrator add description: Role administration adding new entry "cn=Delegation Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: DNS Administrators add description: DNS Administrators adding new entry "cn=DNS Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: DNS Servers add description: DNS Servers adding new entry "cn=DNS Servers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Service Administrators add description: Service Administrators adding new entry "cn=Service Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Automount Administrators add description: Automount Administrators adding new entry "cn=Automount Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Netgroups Administrators add description: Netgroups Administrators adding new entry "cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Certificate Administrators add description: Certificate Administrators adding new entry "cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Replication Administrators add description: Replication Administrators add member: cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test adding new entry "cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Enrollment add description: Host Enrollment adding new entry "cn=Host Enrollment,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Stage User Administrators add description: Stage User Administrators adding new entry "cn=Stage User Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: Stage User Provisioning add description: Stage User Provisioning adding new entry "cn=Stage User Provisioning,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Add Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Modify Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Read Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Remove Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Modify DNA Range add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer add cn: virtual operations adding new entry "cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Retrieve Certificates from the CA add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Request Certificate add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Request Certificates from a different host add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Get Certificates status from the CA add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Revoke Certificate add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames ipapermission add cn: Certificate Remove Hold add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test adding new entry "cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "dc=ufreeipa,dc=test" modify complete add objectClass: top groupofnames nestedgroup add cn: External IdP server Administrators add description: External IdP server Administrators adding new entry "cn=External IdP server Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:21Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:21Z DEBUG step duration: dirsrv __add_delegation_layout 1.10 sec 2025-05-07T18:02:21Z DEBUG [29/45]: creating container for managed entries 2025-05-07T18:02:21Z DEBUG Starting external process 2025-05-07T18:02:21Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpa37cyy8h', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:21Z DEBUG Process finished, return code=0 2025-05-07T18:02:21Z DEBUG stdout=add objectClass: nsContainer top add cn: Managed Entries adding new entry "cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: Templates adding new entry "cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: Definitions adding new entry "cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:21Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:21Z DEBUG step duration: dirsrv __managed_entries 0.07 sec 2025-05-07T18:02:21Z DEBUG [30/45]: configuring user private groups 2025-05-07T18:02:21Z DEBUG Starting external process 2025-05-07T18:02:21Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpiczh1fdo', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:22Z DEBUG Process finished, return code=0 2025-05-07T18:02:22Z DEBUG stdout=add objectclass: mepTemplateEntry add cn: UPG Template add mepRDNAttr: cn add mepStaticAttr: objectclass: posixgroup objectclass: ipaobject ipaUniqueId: autogenerate add mepMappedAttr: cn: $uid gidNumber: $uidNumber description: User private group for $uid adding new entry "cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test" modify complete add objectclass: extensibleObject add cn: UPG Definition add originScope: cn=users,cn=accounts,dc=ufreeipa,dc=test add originFilter: (&(objectclass=posixAccount)(!(description=__no_upg__))) add managedBase: cn=groups,cn=accounts,dc=ufreeipa,dc=test add managedTemplate: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test adding new entry "cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:22Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:22Z DEBUG step duration: dirsrv __user_private_groups 0.35 sec 2025-05-07T18:02:22Z DEBUG [31/45]: configuring netgroups from hostgroups 2025-05-07T18:02:22Z DEBUG Starting external process 2025-05-07T18:02:22Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp6zbgmil1', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:22Z DEBUG Process finished, return code=0 2025-05-07T18:02:22Z DEBUG stdout=add objectclass: mepTemplateEntry add cn: NGP HGP Template add mepRDNAttr: cn add mepStaticAttr: ipaUniqueId: autogenerate objectclass: ipanisnetgroup objectclass: ipaobject nisDomainName: ufreeipa.test add mepMappedAttr: cn: $cn memberHost: $dn description: ipaNetgroup $cn adding new entry "cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test" modify complete add objectclass: extensibleObject add cn: NGP Definition add originScope: cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test add originFilter: objectclass=ipahostgroup add managedBase: cn=ng,cn=alt,dc=ufreeipa,dc=test add managedTemplate: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test adding new entry "cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:22Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:22Z DEBUG step duration: dirsrv __host_nis_groups 0.53 sec 2025-05-07T18:02:22Z DEBUG [32/45]: creating default Sudo bind user 2025-05-07T18:02:22Z DEBUG Starting external process 2025-05-07T18:02:22Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpif6fwt5j', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:23Z DEBUG Process finished, return code=0 2025-05-07T18:02:23Z DEBUG stdout=add objectclass: account simplesecurityobject add uid: sudo add userPassword: XXXXXXXX add passwordExpirationTime: 20380119031407Z add nsIdleTimeout: 0 adding new entry "uid=sudo,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:23Z DEBUG step duration: dirsrv __add_sudo_binduser 0.36 sec 2025-05-07T18:02:23Z DEBUG [33/45]: creating default Auto Member layout 2025-05-07T18:02:23Z DEBUG Starting external process 2025-05-07T18:02:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp_4rkjzw1', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:23Z DEBUG Process finished, return code=0 2025-05-07T18:02:23Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=automember,cn=etc,dc=ufreeipa,dc=test modifying entry "cn=Auto Membership Plugin,cn=plugins,cn=config" modify complete add objectClass: top nsContainer add cn: automember adding new entry "cn=automember,cn=etc,dc=ufreeipa,dc=test" modify complete add objectclass: autoMemberDefinition add cn: Hostgroup add autoMemberScope: cn=computers,cn=accounts,dc=ufreeipa,dc=test add autoMemberFilter: objectclass=ipaHost add autoMemberGroupingAttr: member:dn adding new entry "cn=Hostgroup,cn=automember,cn=etc,dc=ufreeipa,dc=test" modify complete add objectclass: autoMemberDefinition add cn: Group add autoMemberScope: cn=users,cn=accounts,dc=ufreeipa,dc=test add autoMemberFilter: objectclass=posixAccount add autoMemberGroupingAttr: member:dn adding new entry "cn=Group,cn=automember,cn=etc,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:23Z DEBUG step duration: dirsrv __add_automember_config 0.37 sec 2025-05-07T18:02:23Z DEBUG [34/45]: adding range check plugin 2025-05-07T18:02:23Z DEBUG Starting external process 2025-05-07T18:02:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp63j6bkda', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:23Z DEBUG Process finished, return code=0 2025-05-07T18:02:23Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Range-Check add nsslapd-pluginpath: libipa_range_check add nsslapd-plugininitfunc: ipa_range_check_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_range_check_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Range-Check plugin add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=ufreeipa,dc=test adding new entry "cn=IPA Range-Check,cn=plugins,cn=config" modify complete 2025-05-07T18:02:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:23Z DEBUG step duration: dirsrv __add_range_check_plugin 0.28 sec 2025-05-07T18:02:23Z DEBUG [35/45]: creating default HBAC rule allow_all 2025-05-07T18:02:23Z DEBUG Starting external process 2025-05-07T18:02:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpxrnu2gnb', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:23Z DEBUG Process finished, return code=0 2025-05-07T18:02:23Z DEBUG stdout=add objectclass: ipaassociation ipahbacrule add cn: allow_all add accessruletype: allow add usercategory: all add hostcategory: all add servicecategory: all add ipaenabledflag: TRUE add description: Allow all users to access any host from any host add ipauniqueid: autogenerate adding new entry "ipauniqueid=autogenerate,cn=hbac,dc=ufreeipa,dc=test" modify complete add objectclass: ipaassociation ipahbacrule add cn: allow_systemd-user add accessruletype: allow add usercategory: all add hostcategory: all add memberService: cn=systemd-user,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test add ipaenabledflag: TRUE add description: Allow pam_systemd to run user@.service to create a system user session add ipauniqueid: autogenerate adding new entry "ipauniqueid=autogenerate,cn=hbac,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:23Z DEBUG step duration: dirsrv add_hbac 0.06 sec 2025-05-07T18:02:23Z DEBUG [36/45]: adding entries for topology management 2025-05-07T18:02:23Z DEBUG Starting external process 2025-05-07T18:02:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp08ag3kq7', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:24Z DEBUG Process finished, return code=0 2025-05-07T18:02:24Z DEBUG stdout=add objectclass: top nsContainer add cn: topology adding new entry "cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add objectclass: top iparepltopoconf add ipaReplTopoConfRoot: dc=ufreeipa,dc=test add nsDS5ReplicatedAttributeList: (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime add nsDS5ReplicatedAttributeListTotal: (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime add nsds5ReplicaStripAttrs: modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp add cn: domain adding new entry "cn=domain,cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:24Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:24Z DEBUG step duration: dirsrv __add_topology_entries 0.30 sec 2025-05-07T18:02:24Z DEBUG [37/45]: initializing group membership 2025-05-07T18:02:24Z DEBUG Starting external process 2025-05-07T18:02:24Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp5ld1vvcu', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:24Z DEBUG Process finished, return code=0 2025-05-07T18:02:24Z DEBUG stdout=add objectClass: top extensibleObject add cn: IPA install add basedn: dc=ufreeipa,dc=test add filter: (objectclass=*) add ttl: 10 adding new entry "cn=IPA install 1746640923, cn=memberof task, cn=tasks, cn=config" modify complete 2025-05-07T18:02:24Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:24Z DEBUG Waiting for memberof task to complete. 2025-05-07T18:02:24Z DEBUG step duration: dirsrv init_memberof 0.56 sec 2025-05-07T18:02:24Z DEBUG [38/45]: adding master entry 2025-05-07T18:02:24Z DEBUG Starting external process 2025-05-07T18:02:24Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmphrabu4qj', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:24Z DEBUG Process finished, return code=0 2025-05-07T18:02:24Z DEBUG stdout=add objectclass: top nsContainer ipaReplTopoManagedServer ipaConfigObject ipaSupportedDomainLevelConfig add cn: master.ufreeipa.test add ipaReplTopoManagedSuffix: dc=ufreeipa,dc=test add ipaMinDomainLevel: 1 add ipaMaxDomainLevel: 1 adding new entry "cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:24Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:24Z DEBUG step duration: dirsrv __add_master_entry 0.28 sec 2025-05-07T18:02:24Z DEBUG [39/45]: initializing domain level 2025-05-07T18:02:24Z DEBUG Starting external process 2025-05-07T18:02:24Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpmnobdraz', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:25Z DEBUG Process finished, return code=0 2025-05-07T18:02:25Z DEBUG stdout=add objectClass: top nsContainer ipaDomainLevelConfig add ipaDomainLevel: 1 adding new entry "cn=Domain Level,cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:25Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:25Z DEBUG step duration: dirsrv __set_domain_level 0.29 sec 2025-05-07T18:02:25Z DEBUG [40/45]: configuring Posix uid/gid generation 2025-05-07T18:02:25Z DEBUG Starting external process 2025-05-07T18:02:25Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpcn1wlteg', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:25Z DEBUG Process finished, return code=0 2025-05-07T18:02:25Z DEBUG stdout=add objectclass: top extensibleObject add cn: Posix IDs add dnaType: uidNumber gidNumber add dnaNextValue: 63800000 add dnaMaxValue: 63999999 add dnaMagicRegen: -1 add dnaFilter: (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) add dnaScope: dc=ufreeipa,dc=test add dnaThreshold: 500 add dnaSharedCfgDN: cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test add dnaExcludeScope: cn=provisioning,dc=ufreeipa,dc=test adding new entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: Subordinate IDs add dnaType: ipasubuidnumber ipasubgidnumber add dnaNextValue: 2147483648 add dnaMaxValue: 4294836224 add dnaMagicRegen: -1 add dnaFilter: (objectClass=ipaSubordinateId) add dnaScope: dc=ufreeipa,dc=test add dnaThreshold: 500 add dnaSharedCfgDN: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test add dnaExcludeScope: cn=provisioning,dc=ufreeipa,dc=test add dnaInterval: 65536 adding new entry "cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete replace nsslapd-pluginEnabled: on modifying entry "cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete 2025-05-07T18:02:25Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:25Z DEBUG step duration: dirsrv __config_uidgid_gen 0.33 sec 2025-05-07T18:02:25Z DEBUG [41/45]: adding replication acis 2025-05-07T18:02:25Z DEBUG Starting external process 2025-05-07T18:02:25Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmplmfvjvvg', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:25Z DEBUG Process finished, return code=0 2025-05-07T18:02:25Z DEBUG stdout=add aci: (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete add aci: (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add aci: (targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) modifying entry "cn=tasks,cn=config" modify complete 2025-05-07T18:02:25Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:25Z DEBUG step duration: dirsrv __add_replication_acis 0.13 sec 2025-05-07T18:02:25Z DEBUG [42/45]: activating sidgen plugin 2025-05-07T18:02:25Z DEBUG Starting external process 2025-05-07T18:02:25Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp7hcxbp9a', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:25Z DEBUG Process finished, return code=0 2025-05-07T18:02:25Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA SIDGEN add nsslapd-pluginpath: libipa_sidgen add nsslapd-plugininitfunc: ipa_sidgen_init add nsslapd-plugintype: postoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_sidgen_postop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA SIDGEN post operation add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=ufreeipa,dc=test adding new entry "cn=IPA SIDGEN,cn=plugins,cn=config" modify complete 2025-05-07T18:02:25Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:25Z DEBUG step duration: dirsrv _add_sidgen_plugin 0.13 sec 2025-05-07T18:02:25Z DEBUG [43/45]: activating extdom plugin 2025-05-07T18:02:25Z DEBUG Starting external process 2025-05-07T18:02:25Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpa3zuexrm', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:26Z DEBUG Process finished, return code=0 2025-05-07T18:02:26Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_extdom_extop add nsslapd-pluginpath: libipa_extdom_extop add nsslapd-plugininitfunc: ipa_extdom_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_extdom_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support resolving IDs in trusted domains to names and back add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=ufreeipa,dc=test adding new entry "cn=ipa_extdom_extop,cn=plugins,cn=config" modify complete 2025-05-07T18:02:26Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:26Z DEBUG step duration: dirsrv _add_extdom_plugin 0.28 sec 2025-05-07T18:02:26Z DEBUG [44/45]: configuring directory to start on boot 2025-05-07T18:02:26Z DEBUG Starting external process 2025-05-07T18:02:26Z DEBUG args=['/bin/systemctl', 'is-enabled', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:26Z DEBUG Process finished, return code=0 2025-05-07T18:02:26Z DEBUG stdout=enabled 2025-05-07T18:02:26Z DEBUG stderr= 2025-05-07T18:02:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:26Z DEBUG Starting external process 2025-05-07T18:02:26Z DEBUG args=['/bin/systemctl', 'disable', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:26Z DEBUG Process finished, return code=0 2025-05-07T18:02:26Z DEBUG stdout= 2025-05-07T18:02:26Z DEBUG stderr=Removed '/etc/systemd/system/multi-user.target.wants/dirsrv@UFREEIPA-TEST.service'. Removed '/etc/systemd/system/dirsrv.target.wants/dirsrv@UFREEIPA-TEST.service'. 2025-05-07T18:02:26Z DEBUG step duration: dirsrv __enable 0.34 sec 2025-05-07T18:02:26Z DEBUG [45/45]: restarting directory server 2025-05-07T18:02:26Z DEBUG Destroyed connection context.ldap2_139937138938208 2025-05-07T18:02:26Z DEBUG Starting external process 2025-05-07T18:02:26Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2025-05-07T18:02:26Z DEBUG Process finished, return code=0 2025-05-07T18:02:26Z DEBUG stdout= 2025-05-07T18:02:26Z DEBUG stderr= 2025-05-07T18:02:26Z DEBUG Starting external process 2025-05-07T18:02:26Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:27Z DEBUG Process finished, return code=0 2025-05-07T18:02:27Z DEBUG stdout= 2025-05-07T18:02:27Z DEBUG stderr= 2025-05-07T18:02:27Z DEBUG Starting external process 2025-05-07T18:02:27Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:27Z DEBUG Process finished, return code=0 2025-05-07T18:02:27Z DEBUG stdout=active 2025-05-07T18:02:27Z DEBUG stderr= 2025-05-07T18:02:27Z DEBUG wait_for_open_ports: localhost [389] timeout 90 2025-05-07T18:02:27Z DEBUG waiting for port: 389 2025-05-07T18:02:27Z DEBUG SUCCESS: port: 389 2025-05-07T18:02:27Z DEBUG Restart of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:02:27Z DEBUG Starting external process 2025-05-07T18:02:27Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:02:27Z DEBUG Process finished, return code=0 2025-05-07T18:02:27Z DEBUG stdout=active 2025-05-07T18:02:27Z DEBUG stderr= 2025-05-07T18:02:27Z DEBUG Created connection context.ldap2_139937138938208 2025-05-07T18:02:27Z DEBUG step duration: dirsrv __restart_instance 1.53 sec 2025-05-07T18:02:27Z DEBUG Done configuring directory server (dirsrv). 2025-05-07T18:02:27Z DEBUG service duration: dirsrv 24.70 sec 2025-05-07T18:02:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:28Z DEBUG Starting external process 2025-05-07T18:02:28Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2025-05-07T18:02:28Z DEBUG Process finished, return code=0 2025-05-07T18:02:28Z DEBUG stdout=679872031 2025-05-07T18:02:28Z DEBUG stderr= 2025-05-07T18:02:28Z DEBUG Enabling persistent keyring CCACHE 2025-05-07T18:02:28Z DEBUG Starting external process 2025-05-07T18:02:28Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2025-05-07T18:02:28Z DEBUG Process finished, return code=3 2025-05-07T18:02:28Z DEBUG stdout=inactive 2025-05-07T18:02:28Z DEBUG stderr= 2025-05-07T18:02:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:28Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:28Z DEBUG Starting external process 2025-05-07T18:02:28Z DEBUG args=['/bin/systemctl', 'stop', 'krb5kdc.service'] 2025-05-07T18:02:28Z DEBUG Process finished, return code=0 2025-05-07T18:02:28Z DEBUG stdout= 2025-05-07T18:02:28Z DEBUG stderr= 2025-05-07T18:02:28Z DEBUG Stop of krb5kdc.service complete 2025-05-07T18:02:28Z DEBUG Configuring Kerberos KDC (krb5kdc) 2025-05-07T18:02:28Z DEBUG [1/11]: adding kerberos container to the directory 2025-05-07T18:02:28Z DEBUG Starting external process 2025-05-07T18:02:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpl0bc7j_r', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:28Z DEBUG Process finished, return code=0 2025-05-07T18:02:28Z DEBUG stdout=add objectClass: krbContainer top add cn: kerberos adding new entry "cn=kerberos,dc=ufreeipa,dc=test" modify complete add cn: UFREEIPA.TEST add objectClass: top krbrealmcontainer krbticketpolicyaux add krbSubTrees: dc=ufreeipa,dc=test add krbSearchScope: 2 add krbSupportedEncSaltTypes: aes256-cts:normal aes256-cts:special aes128-cts:normal aes128-cts:special aes128-sha2:normal aes128-sha2:special aes256-sha2:normal aes256-sha2:special camellia128-cts-cmac:normal camellia128-cts-cmac:special camellia256-cts-cmac:normal camellia256-cts-cmac:special add krbMaxTicketLife: 86400 add krbMaxRenewableAge: 604800 add krbDefaultEncSaltTypes: aes256-sha2:special aes128-sha2:special aes256-cts:special aes128-cts:special adding new entry "cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test" modify complete add objectClass: top nsContainer krbPwdPolicy ipaPwdPolicy add krbMinPwdLife: 3600 add krbPwdMinDiffChars: 0 add krbPwdMinLength: 8 add krbPwdHistoryLength: 0 add krbMaxPwdLife: 7776000 add krbPwdMaxFailure: 6 add krbPwdFailureCountInterval: 60 add krbPwdLockoutDuration: 600 add passwordGraceLimit: -1 adding new entry "cn=global_policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:28Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:28Z DEBUG step duration: krb5kdc __add_krb_container 0.33 sec 2025-05-07T18:02:28Z DEBUG [2/11]: configuring KDC 2025-05-07T18:02:28Z DEBUG Backing up system configuration file '/var/kerberos/krb5kdc/kdc.conf' 2025-05-07T18:02:28Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:02:28Z DEBUG Backing up system configuration file '/etc/krb5.conf' 2025-05-07T18:02:28Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:02:28Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa-server' 2025-05-07T18:02:28Z DEBUG -> Not backing up - '/etc/krb5.conf.d/freeipa-server' doesn't exist 2025-05-07T18:02:28Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa' 2025-05-07T18:02:28Z DEBUG -> Not backing up - '/etc/krb5.conf.d/freeipa' doesn't exist 2025-05-07T18:02:28Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb5.ini' 2025-05-07T18:02:28Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb5.ini' doesn't exist 2025-05-07T18:02:28Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb.con' 2025-05-07T18:02:28Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb.con' doesn't exist 2025-05-07T18:02:28Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krbrealm.con' 2025-05-07T18:02:28Z DEBUG -> Not backing up - '/usr/share/ipa/html/krbrealm.con' doesn't exist 2025-05-07T18:02:28Z DEBUG Starting external process 2025-05-07T18:02:28Z DEBUG args=['/usr/bin/klist', '-V'] 2025-05-07T18:02:28Z DEBUG Process finished, return code=0 2025-05-07T18:02:28Z DEBUG stdout=Kerberos 5 version 1.21.3 2025-05-07T18:02:28Z DEBUG stderr= 2025-05-07T18:02:28Z DEBUG Backing up system configuration file '/etc/sysconfig/krb5kdc' 2025-05-07T18:02:28Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:02:28Z DEBUG Starting external process 2025-05-07T18:02:28Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:02:28Z DEBUG Process finished, return code=0 2025-05-07T18:02:28Z DEBUG stdout= 2025-05-07T18:02:28Z DEBUG stderr= 2025-05-07T18:02:28Z DEBUG Starting external process 2025-05-07T18:02:28Z DEBUG args=['/sbin/restorecon', '/etc/sysconfig/krb5kdc'] 2025-05-07T18:02:28Z DEBUG Process finished, return code=0 2025-05-07T18:02:28Z DEBUG stdout= 2025-05-07T18:02:28Z DEBUG stderr= 2025-05-07T18:02:28Z DEBUG step duration: krb5kdc __configure_instance 0.02 sec 2025-05-07T18:02:28Z DEBUG [3/11]: initialize kerberos container 2025-05-07T18:02:28Z DEBUG Starting external process 2025-05-07T18:02:28Z DEBUG args=['kdb5_util', 'create', '-s', '-r', 'UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:02:29Z DEBUG Process finished, return code=0 2025-05-07T18:02:29Z DEBUG stdout=Initializing database '/var/kerberos/krb5kdc/principal' for realm 'UFREEIPA.TEST', master key name 'K/M@UFREEIPA.TEST' You will be prompted for the database Master Password. It is important that you NOT FORGET this password. Enter KDC database master key: Re-enter KDC database master key to verify: 2025-05-07T18:02:29Z DEBUG stderr= 2025-05-07T18:02:29Z DEBUG step duration: krb5kdc __init_ipa_kdb 0.82 sec 2025-05-07T18:02:29Z DEBUG [4/11]: adding default ACIs 2025-05-07T18:02:29Z DEBUG Starting external process 2025-05-07T18:02:29Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp5zekq2pn', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:29Z DEBUG Process finished, return code=0 2025-05-07T18:02:29Z DEBUG stdout=add aci: (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) modifying entry "dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) modifying entry "dc=ufreeipa,dc=test" modify complete add aci: (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) modifying entry "cn=etc,dc=ufreeipa,dc=test" modify complete add aci: (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) modifying entry "cn=ipa,cn=etc,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) modifying entry "cn=accounts,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) modifying entry "cn=services,cn=accounts,dc=ufreeipa,dc=test" modify complete add aci: (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) modifying entry "cn=services,cn=accounts,dc=ufreeipa,dc=test" modify complete add aci: (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) modifying entry "cn=computers,cn=accounts,dc=ufreeipa,dc=test" modify complete add aci: (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) modifying entry "cn=computers,cn=accounts,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) modifying entry "cn=computers,cn=accounts,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) modifying entry "cn=groups,cn=accounts,dc=ufreeipa,dc=test" modify complete add aci: (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) modifying entry "cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" modify complete add aci: (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) modifying entry "cn=accounts,dc=ufreeipa,dc=test" modify complete add aci: (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) modifying entry "dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:29Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:29Z DEBUG step duration: krb5kdc __add_default_acis 0.50 sec 2025-05-07T18:02:29Z DEBUG [5/11]: creating a keytab for the directory 2025-05-07T18:02:29Z DEBUG Starting external process 2025-05-07T18:02:29Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey ldap/master.ufreeipa.test@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:02:30Z DEBUG Process finished, return code=0 2025-05-07T18:02:30Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Principal "ldap/master.ufreeipa.test@UFREEIPA.TEST" created. 2025-05-07T18:02:30Z DEBUG stderr=No policy specified for ldap/master.ufreeipa.test@UFREEIPA.TEST; defaulting to no policy 2025-05-07T18:02:30Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:02:30Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:02:30Z DEBUG Backing up system configuration file '/etc/dirsrv/ds.keytab' 2025-05-07T18:02:30Z DEBUG -> Not backing up - '/etc/dirsrv/ds.keytab' doesn't exist 2025-05-07T18:02:30Z DEBUG Starting external process 2025-05-07T18:02:30Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/dirsrv/ds.keytab ldap/master.ufreeipa.test@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:02:31Z DEBUG Process finished, return code=0 2025-05-07T18:02:31Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Entry for principal ldap/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab. 2025-05-07T18:02:31Z DEBUG stderr= 2025-05-07T18:02:31Z DEBUG step duration: krb5kdc __create_ds_keytab 1.29 sec 2025-05-07T18:02:31Z DEBUG [6/11]: creating a keytab for the machine 2025-05-07T18:02:31Z DEBUG Starting external process 2025-05-07T18:02:31Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey host/master.ufreeipa.test@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:02:31Z DEBUG Process finished, return code=0 2025-05-07T18:02:31Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Principal "host/master.ufreeipa.test@UFREEIPA.TEST" created. 2025-05-07T18:02:31Z DEBUG stderr=No policy specified for host/master.ufreeipa.test@UFREEIPA.TEST; defaulting to no policy 2025-05-07T18:02:31Z DEBUG Backing up system configuration file '/etc/krb5.keytab' 2025-05-07T18:02:31Z DEBUG -> Not backing up - '/etc/krb5.keytab' doesn't exist 2025-05-07T18:02:31Z DEBUG Starting external process 2025-05-07T18:02:31Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/krb5.keytab host/master.ufreeipa.test@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:02:31Z DEBUG Process finished, return code=0 2025-05-07T18:02:31Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Entry for principal host/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/krb5.keytab. 2025-05-07T18:02:31Z DEBUG stderr= 2025-05-07T18:02:31Z DEBUG importing all plugin modules in ipaserver.plugins... 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.aci 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.automember 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.automount 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.baseldap 2025-05-07T18:02:31Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.baseuser 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.batch 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.ca 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.caacl 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.cert 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.certmap 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.certprofile 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.config 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.delegation 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.dns 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.dogtag 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.group 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.hbac 2025-05-07T18:02:31Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.hbactest 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.host 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.idp 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.idrange 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.idviews 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.internal 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.join 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.ldap2 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.location 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.migration 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.misc 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.netgroup 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.otp 2025-05-07T18:02:31Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.otptoken 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.passkeyconfig 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.passwd 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.permission 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.ping 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.pkinit 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.privilege 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.rabase 2025-05-07T18:02:31Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.role 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.schema 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.selfservice 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.server 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.serverrole 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.serverroles 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.service 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.session 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.stageuser 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.subid 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.sudo 2025-05-07T18:02:31Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.sudorule 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.topology 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.trust 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.user 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.vault 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.virtual 2025-05-07T18:02:31Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.whoami 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2025-05-07T18:02:31Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.dns 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_subid_support 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2025-05-07T18:02:31Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2025-05-07T18:02:32Z DEBUG Created connection context.ldap2_139937109398288 2025-05-07T18:02:32Z DEBUG raw: idrange_show('UFREEIPA.TEST_id_range', version='2.254') 2025-05-07T18:02:32Z DEBUG idrange_show('UFREEIPA.TEST_id_range', rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:02:32Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:02:32Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:02:32Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2025-05-07T18:02:32Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:02:32Z DEBUG --------------------------------------------- 2025-05-07T18:02:32Z DEBUG Initial value 2025-05-07T18:02:32Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:02:32Z DEBUG objectClass: 2025-05-07T18:02:32Z DEBUG top 2025-05-07T18:02:32Z DEBUG groupOfNames 2025-05-07T18:02:32Z DEBUG nestedGroup 2025-05-07T18:02:32Z DEBUG ipaobject 2025-05-07T18:02:32Z DEBUG ipahostgroup 2025-05-07T18:02:32Z DEBUG description: 2025-05-07T18:02:32Z DEBUG IPA server hosts 2025-05-07T18:02:32Z DEBUG cn: 2025-05-07T18:02:32Z DEBUG ipaservers 2025-05-07T18:02:32Z DEBUG ipaUniqueID: 2025-05-07T18:02:32Z DEBUG 6b730f14-2b6d-11f0-9ff4-fa163e36f7a6 2025-05-07T18:02:32Z DEBUG --------------------------------------------- 2025-05-07T18:02:32Z DEBUG Final value after applying updates 2025-05-07T18:02:32Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:02:32Z DEBUG objectClass: 2025-05-07T18:02:32Z DEBUG top 2025-05-07T18:02:32Z DEBUG groupOfNames 2025-05-07T18:02:32Z DEBUG nestedGroup 2025-05-07T18:02:32Z DEBUG ipaobject 2025-05-07T18:02:32Z DEBUG ipahostgroup 2025-05-07T18:02:32Z DEBUG description: 2025-05-07T18:02:32Z DEBUG IPA server hosts 2025-05-07T18:02:32Z DEBUG cn: 2025-05-07T18:02:32Z DEBUG ipaservers 2025-05-07T18:02:32Z DEBUG ipaUniqueID: 2025-05-07T18:02:32Z DEBUG 6b730f14-2b6d-11f0-9ff4-fa163e36f7a6 2025-05-07T18:02:32Z DEBUG [] 2025-05-07T18:02:32Z DEBUG Updated 0 2025-05-07T18:02:32Z DEBUG Done 2025-05-07T18:02:32Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:02:32Z DEBUG --------------------------------------------- 2025-05-07T18:02:32Z DEBUG Initial value 2025-05-07T18:02:32Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:02:32Z DEBUG objectClass: 2025-05-07T18:02:32Z DEBUG top 2025-05-07T18:02:32Z DEBUG groupOfNames 2025-05-07T18:02:32Z DEBUG nestedGroup 2025-05-07T18:02:32Z DEBUG ipaobject 2025-05-07T18:02:32Z DEBUG ipahostgroup 2025-05-07T18:02:32Z DEBUG description: 2025-05-07T18:02:32Z DEBUG IPA server hosts 2025-05-07T18:02:32Z DEBUG cn: 2025-05-07T18:02:32Z DEBUG ipaservers 2025-05-07T18:02:32Z DEBUG ipaUniqueID: 2025-05-07T18:02:32Z DEBUG 6b730f14-2b6d-11f0-9ff4-fa163e36f7a6 2025-05-07T18:02:32Z DEBUG add: 'fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:02:32Z DEBUG add: updated value ['fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:02:32Z DEBUG --------------------------------------------- 2025-05-07T18:02:32Z DEBUG Final value after applying updates 2025-05-07T18:02:32Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:02:32Z DEBUG objectClass: 2025-05-07T18:02:32Z DEBUG top 2025-05-07T18:02:32Z DEBUG groupOfNames 2025-05-07T18:02:32Z DEBUG nestedGroup 2025-05-07T18:02:32Z DEBUG ipaobject 2025-05-07T18:02:32Z DEBUG ipahostgroup 2025-05-07T18:02:32Z DEBUG description: 2025-05-07T18:02:32Z DEBUG IPA server hosts 2025-05-07T18:02:32Z DEBUG cn: 2025-05-07T18:02:32Z DEBUG ipaservers 2025-05-07T18:02:32Z DEBUG ipaUniqueID: 2025-05-07T18:02:32Z DEBUG 6b730f14-2b6d-11f0-9ff4-fa163e36f7a6 2025-05-07T18:02:32Z DEBUG member: 2025-05-07T18:02:32Z DEBUG fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:02:32Z DEBUG [(2, 'member', ['fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:02:32Z DEBUG Updated 1 2025-05-07T18:02:32Z DEBUG update_entry modlist [(2, 'member', [b'fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:02:32Z DEBUG Done 2025-05-07T18:02:32Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-ipaservers_hostgroup.update 0.038 sec 2025-05-07T18:02:32Z DEBUG Destroyed connection context.ldap2_139937109398288 2025-05-07T18:02:32Z DEBUG step duration: krb5kdc __create_host_keytab 1.48 sec 2025-05-07T18:02:32Z DEBUG [7/11]: adding the password extension to the directory 2025-05-07T18:02:32Z DEBUG Starting external process 2025-05-07T18:02:32Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpkzndf3xg', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:32Z DEBUG Process finished, return code=0 2025-05-07T18:02:32Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_pwd_extop add nsslapd-pluginpath: libipa_pwd_extop add nsslapd-plugininitfunc: ipapwd_init add nsslapd-plugintype: extendedop add nsslapd-pluginbetxn: on add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_pwd_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support saving passwords in multiple formats for different consumers (krb5, samba, freeradius, etc.) add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=ufreeipa,dc=test adding new entry "cn=ipa_pwd_extop,cn=plugins,cn=config" modify complete 2025-05-07T18:02:32Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:32Z DEBUG step duration: krb5kdc __add_pwd_extop_module 0.05 sec 2025-05-07T18:02:32Z DEBUG [8/11]: creating anonymous principal 2025-05-07T18:02:32Z DEBUG Starting external process 2025-05-07T18:02:32Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey WELLKNOWN/ANONYMOUS@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:02:33Z DEBUG Process finished, return code=0 2025-05-07T18:02:33Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Principal "WELLKNOWN/ANONYMOUS@UFREEIPA.TEST" created. 2025-05-07T18:02:33Z DEBUG stderr=No policy specified for WELLKNOWN/ANONYMOUS@UFREEIPA.TEST; defaulting to no policy 2025-05-07T18:02:33Z DEBUG Starting external process 2025-05-07T18:02:33Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpqnix6vma', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:02:33Z DEBUG Process finished, return code=0 2025-05-07T18:02:33Z DEBUG stdout=add objectclass: ipaAllowedOperations add aci: (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) add ipaAllowedToPerform;read_keys: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test modifying entry "krbPrincipalName=WELLKNOWN/ANONYMOUS@UFREEIPA.TEST,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:02:33Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:02:33Z DEBUG step duration: krb5kdc add_anonymous_principal 0.81 sec 2025-05-07T18:02:33Z DEBUG [9/11]: starting the KDC 2025-05-07T18:02:33Z DEBUG Starting external process 2025-05-07T18:02:33Z DEBUG args=['/bin/systemctl', 'start', 'krb5kdc.service'] 2025-05-07T18:02:33Z DEBUG Process finished, return code=0 2025-05-07T18:02:33Z DEBUG stdout= 2025-05-07T18:02:33Z DEBUG stderr= 2025-05-07T18:02:33Z DEBUG Starting external process 2025-05-07T18:02:33Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2025-05-07T18:02:33Z DEBUG Process finished, return code=0 2025-05-07T18:02:33Z DEBUG stdout=active 2025-05-07T18:02:33Z DEBUG stderr= 2025-05-07T18:02:33Z DEBUG Start of krb5kdc.service complete 2025-05-07T18:02:33Z DEBUG step duration: krb5kdc __start_instance 0.39 sec 2025-05-07T18:02:33Z DEBUG [10/11]: configuring KDC to start on boot 2025-05-07T18:02:33Z DEBUG Starting external process 2025-05-07T18:02:33Z DEBUG args=['/bin/systemctl', 'is-enabled', 'krb5kdc.service'] 2025-05-07T18:02:33Z DEBUG Process finished, return code=1 2025-05-07T18:02:33Z DEBUG stdout=disabled 2025-05-07T18:02:33Z DEBUG stderr= 2025-05-07T18:02:33Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:33Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:33Z DEBUG Starting external process 2025-05-07T18:02:33Z DEBUG args=['/bin/systemctl', 'unmask', 'krb5kdc.service'] 2025-05-07T18:02:34Z DEBUG Process finished, return code=0 2025-05-07T18:02:34Z DEBUG stdout= 2025-05-07T18:02:34Z DEBUG stderr= 2025-05-07T18:02:34Z DEBUG Starting external process 2025-05-07T18:02:34Z DEBUG args=['/bin/systemctl', 'disable', 'krb5kdc.service'] 2025-05-07T18:02:34Z DEBUG Process finished, return code=0 2025-05-07T18:02:34Z DEBUG stdout= 2025-05-07T18:02:34Z DEBUG stderr= 2025-05-07T18:02:34Z DEBUG step duration: krb5kdc __enable 0.71 sec 2025-05-07T18:02:34Z DEBUG [11/11]: enable PAC ticket signature support 2025-05-07T18:02:34Z DEBUG update_entry modlist [(0, 'ipaconfigstring', [b'pacTktSignSupported'])] 2025-05-07T18:02:34Z DEBUG service KDC has all config values set 2025-05-07T18:02:34Z DEBUG step duration: krb5kdc pac_tkt_sign_support_enable 0.02 sec 2025-05-07T18:02:34Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2025-05-07T18:02:34Z DEBUG service duration: krb5kdc 6.46 sec 2025-05-07T18:02:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:34Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:02:34Z DEBUG Configuring kadmin 2025-05-07T18:02:34Z DEBUG [1/2]: starting kadmin 2025-05-07T18:02:34Z DEBUG Starting external process 2025-05-07T18:02:34Z DEBUG args=['/bin/systemctl', 'is-active', 'kadmin.service'] 2025-05-07T18:02:34Z DEBUG Process finished, return code=3 2025-05-07T18:02:34Z DEBUG stdout=inactive 2025-05-07T18:02:34Z DEBUG stderr= 2025-05-07T18:02:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:34Z DEBUG Starting external process 2025-05-07T18:02:34Z DEBUG args=['/bin/systemctl', 'restart', 'kadmin.service'] 2025-05-07T18:02:34Z DEBUG Process finished, return code=0 2025-05-07T18:02:34Z DEBUG stdout= 2025-05-07T18:02:34Z DEBUG stderr= 2025-05-07T18:02:34Z DEBUG Starting external process 2025-05-07T18:02:34Z DEBUG args=['/bin/systemctl', 'is-active', 'kadmin.service'] 2025-05-07T18:02:34Z DEBUG Process finished, return code=0 2025-05-07T18:02:34Z DEBUG stdout=active 2025-05-07T18:02:34Z DEBUG stderr= 2025-05-07T18:02:34Z DEBUG Restart of kadmin.service complete 2025-05-07T18:02:34Z DEBUG step duration: kadmin __start 0.32 sec 2025-05-07T18:02:34Z DEBUG [2/2]: configuring kadmin to start on boot 2025-05-07T18:02:34Z DEBUG Starting external process 2025-05-07T18:02:34Z DEBUG args=['/bin/systemctl', 'is-enabled', 'kadmin.service'] 2025-05-07T18:02:34Z DEBUG Process finished, return code=1 2025-05-07T18:02:34Z DEBUG stdout=disabled 2025-05-07T18:02:34Z DEBUG stderr= 2025-05-07T18:02:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:34Z DEBUG Starting external process 2025-05-07T18:02:34Z DEBUG args=['/bin/systemctl', 'unmask', 'kadmin.service'] 2025-05-07T18:02:35Z DEBUG Process finished, return code=0 2025-05-07T18:02:35Z DEBUG stdout= 2025-05-07T18:02:35Z DEBUG stderr= 2025-05-07T18:02:35Z DEBUG Starting external process 2025-05-07T18:02:35Z DEBUG args=['/bin/systemctl', 'disable', 'kadmin.service'] 2025-05-07T18:02:35Z DEBUG Process finished, return code=0 2025-05-07T18:02:35Z DEBUG stdout= 2025-05-07T18:02:35Z DEBUG stderr= 2025-05-07T18:02:35Z DEBUG step duration: kadmin __enable 0.72 sec 2025-05-07T18:02:35Z DEBUG Done configuring kadmin. 2025-05-07T18:02:35Z DEBUG service duration: kadmin 1.04 sec 2025-05-07T18:02:35Z DEBUG Custodia client for '' with promotion no. 2025-05-07T18:02:35Z DEBUG Custodia uses LDAPI. 2025-05-07T18:02:35Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:35Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:02:35Z DEBUG Configuring ipa-custodia 2025-05-07T18:02:35Z DEBUG [1/5]: Making sure custodia container exists 2025-05-07T18:02:35Z DEBUG importing all plugin modules in ipaserver.plugins... 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.aci 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.automember 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.automount 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.baseldap 2025-05-07T18:02:35Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.baseuser 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.batch 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.ca 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.caacl 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.cert 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.certmap 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.certprofile 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.config 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.delegation 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.dns 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.dogtag 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.group 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.hbac 2025-05-07T18:02:35Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.hbactest 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.host 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.idp 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.idrange 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.idviews 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.internal 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.join 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.ldap2 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.location 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.migration 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.misc 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.netgroup 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.otp 2025-05-07T18:02:35Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.otptoken 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.passkeyconfig 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.passwd 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.permission 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.ping 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.pkinit 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.privilege 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.rabase 2025-05-07T18:02:35Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.role 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.schema 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.selfservice 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.server 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.serverrole 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.serverroles 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.service 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.session 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.stageuser 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.subid 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.sudo 2025-05-07T18:02:35Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.sudorule 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.topology 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.trust 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.user 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.vault 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.virtual 2025-05-07T18:02:35Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.whoami 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2025-05-07T18:02:35Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.dns 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_subid_support 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2025-05-07T18:02:35Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2025-05-07T18:02:36Z DEBUG Created connection context.ldap2_139937097938368 2025-05-07T18:02:36Z DEBUG raw: idrange_show('UFREEIPA.TEST_id_range', version='2.254') 2025-05-07T18:02:36Z DEBUG idrange_show('UFREEIPA.TEST_id_range', rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:02:36Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:02:36Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:02:36Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2025-05-07T18:02:36Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:02:36Z DEBUG --------------------------------------------- 2025-05-07T18:02:36Z DEBUG Initial value 2025-05-07T18:02:36Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:02:36Z DEBUG objectClass: 2025-05-07T18:02:36Z DEBUG nsContainer 2025-05-07T18:02:36Z DEBUG top 2025-05-07T18:02:36Z DEBUG cn: 2025-05-07T18:02:36Z DEBUG custodia 2025-05-07T18:02:36Z DEBUG --------------------------------------------- 2025-05-07T18:02:36Z DEBUG Final value after applying updates 2025-05-07T18:02:36Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:02:36Z DEBUG objectClass: 2025-05-07T18:02:36Z DEBUG nsContainer 2025-05-07T18:02:36Z DEBUG top 2025-05-07T18:02:36Z DEBUG cn: 2025-05-07T18:02:36Z DEBUG custodia 2025-05-07T18:02:36Z DEBUG [] 2025-05-07T18:02:36Z DEBUG Updated 0 2025-05-07T18:02:36Z DEBUG Done 2025-05-07T18:02:36Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:02:36Z DEBUG --------------------------------------------- 2025-05-07T18:02:36Z DEBUG Initial value 2025-05-07T18:02:36Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:02:36Z DEBUG objectClass: 2025-05-07T18:02:36Z DEBUG nsContainer 2025-05-07T18:02:36Z DEBUG top 2025-05-07T18:02:36Z DEBUG cn: 2025-05-07T18:02:36Z DEBUG dogtag 2025-05-07T18:02:36Z DEBUG --------------------------------------------- 2025-05-07T18:02:36Z DEBUG Final value after applying updates 2025-05-07T18:02:36Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:02:36Z DEBUG objectClass: 2025-05-07T18:02:36Z DEBUG nsContainer 2025-05-07T18:02:36Z DEBUG top 2025-05-07T18:02:36Z DEBUG cn: 2025-05-07T18:02:36Z DEBUG dogtag 2025-05-07T18:02:36Z DEBUG [] 2025-05-07T18:02:36Z DEBUG Updated 0 2025-05-07T18:02:36Z DEBUG Done 2025-05-07T18:02:36Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-custodia.update 0.016 sec 2025-05-07T18:02:36Z DEBUG Destroyed connection context.ldap2_139937097938368 2025-05-07T18:02:36Z DEBUG step duration: ipa-custodia __create_container 0.88 sec 2025-05-07T18:02:36Z DEBUG [2/5]: Generating ipa-custodia config file 2025-05-07T18:02:36Z DEBUG step duration: ipa-custodia __config_file 0.01 sec 2025-05-07T18:02:36Z DEBUG [3/5]: Generating ipa-custodia keys 2025-05-07T18:02:36Z DEBUG step duration: ipa-custodia __gen_keys 0.50 sec 2025-05-07T18:02:36Z DEBUG [4/5]: starting ipa-custodia 2025-05-07T18:02:36Z DEBUG Starting external process 2025-05-07T18:02:36Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2025-05-07T18:02:36Z DEBUG Process finished, return code=3 2025-05-07T18:02:36Z DEBUG stdout=inactive 2025-05-07T18:02:36Z DEBUG stderr= 2025-05-07T18:02:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:36Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:36Z DEBUG Starting external process 2025-05-07T18:02:36Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-custodia.service'] 2025-05-07T18:02:37Z DEBUG Process finished, return code=0 2025-05-07T18:02:37Z DEBUG stdout= 2025-05-07T18:02:37Z DEBUG stderr= 2025-05-07T18:02:37Z DEBUG Starting external process 2025-05-07T18:02:37Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2025-05-07T18:02:37Z DEBUG Process finished, return code=0 2025-05-07T18:02:37Z DEBUG stdout=active 2025-05-07T18:02:37Z DEBUG stderr= 2025-05-07T18:02:37Z DEBUG Restart of ipa-custodia.service complete 2025-05-07T18:02:37Z DEBUG step duration: ipa-custodia __start 0.38 sec 2025-05-07T18:02:37Z DEBUG [5/5]: configuring ipa-custodia to start on boot 2025-05-07T18:02:37Z DEBUG Starting external process 2025-05-07T18:02:37Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ipa-custodia.service'] 2025-05-07T18:02:37Z DEBUG Process finished, return code=1 2025-05-07T18:02:37Z DEBUG stdout=disabled 2025-05-07T18:02:37Z DEBUG stderr= 2025-05-07T18:02:37Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:37Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:37Z DEBUG Starting external process 2025-05-07T18:02:37Z DEBUG args=['/bin/systemctl', 'unmask', 'ipa-custodia.service'] 2025-05-07T18:02:37Z DEBUG Process finished, return code=0 2025-05-07T18:02:37Z DEBUG stdout= 2025-05-07T18:02:37Z DEBUG stderr= 2025-05-07T18:02:37Z DEBUG Starting external process 2025-05-07T18:02:37Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-custodia.service'] 2025-05-07T18:02:37Z DEBUG Process finished, return code=0 2025-05-07T18:02:37Z DEBUG stdout= 2025-05-07T18:02:37Z DEBUG stderr= 2025-05-07T18:02:38Z DEBUG step duration: ipa-custodia __enable 0.72 sec 2025-05-07T18:02:38Z DEBUG Done configuring ipa-custodia. 2025-05-07T18:02:38Z DEBUG service duration: ipa-custodia 2.49 sec 2025-05-07T18:02:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:02:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:02:38Z DEBUG update_entry modlist [(2, 'ipacertificatesubjectbase', [b'O=UFREEIPA.TEST'])] 2025-05-07T18:02:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:02:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:02:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:38Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:02:38Z INFO Forcing random serial numbers to be enabled for the mdb backend 2025-05-07T18:02:38Z DEBUG Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes 2025-05-07T18:02:38Z DEBUG [1/33]: configuring certificate server instance 2025-05-07T18:02:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:02:38Z DEBUG Contents of pkispawn configuration file (/tmp/tmpr1fhan9i): [CA] pki_admin_cert_file = /root/.dogtag/pki-tomcat/ca_admin.cert pki_admin_cert_request_type = pkcs10 pki_admin_dualkey = False pki_admin_email = root@localhost pki_admin_name = admin pki_admin_nickname = ipa-ca-agent pki_admin_password = XXXXXXXX pki_admin_subject_dn = cn=ipa-ca-agent,O=UFREEIPA.TEST pki_admin_uid = admin pki_ajp_host_ipv4 = 127.0.0.1 pki_ajp_host_ipv6 = ::1 pki_ajp_secret = 5VsZxV4lJeXZbe1aTK1wha4m29Sbfei1qVJzKkasTSZk pki_audit_group = pkiaudit pki_audit_signing_key_algorithm = SHA256withRSA pki_audit_signing_key_size = 2048 pki_audit_signing_key_type = rsa pki_audit_signing_nickname = auditSigningCert cert-pki-ca pki_audit_signing_signing_algorithm = SHA256withRSA pki_audit_signing_subject_dn = cn=CA Audit,O=UFREEIPA.TEST pki_audit_signing_token = internal pki_backup_keys = True pki_backup_password = XXXXXXXX pki_ca_hostname = master.ufreeipa.test pki_ca_port = 443 pki_ca_signing_cert_path = pki_ca_signing_csr_path = pki_ca_signing_key_algorithm = SHA256withRSA pki_ca_signing_key_size = 3072 pki_ca_signing_key_type = rsa pki_ca_signing_nickname = caSigningCert cert-pki-ca pki_ca_signing_record_create = True pki_ca_signing_serial_number = 1 pki_ca_signing_signing_algorithm = SHA256withRSA pki_ca_signing_subject_dn = CN=Certificate Authority,O=UFREEIPA.TEST pki_ca_signing_token = internal pki_ca_starting_crl_number = 0 pki_cert_chain_nickname = caSigningCert External CA pki_cert_chain_path = pki_cert_id_generator = random pki_client_admin_cert_p12 = /root/ca-agent.p12 pki_client_database_password = pki_client_database_purge = True pki_client_dir = /root/.dogtag/pki-tomcat pki_client_pkcs12_password = XXXXXXXX pki_configuration_path = /etc/pki pki_default_ocsp_uri = http://ipa-ca.ufreeipa.test/ca/ocsp pki_dns_domainname = ufreeipa.test pki_ds_base_dn = o=ipaca pki_ds_bind_dn = cn=Directory Manager pki_ds_database = ipaca pki_ds_hostname = master.ufreeipa.test pki_ds_ldap_port = 389 pki_ds_ldaps_port = 636 pki_ds_password = XXXXXXXX pki_ds_remove_data = True pki_ds_secure_connection = False pki_ds_secure_connection_ca_nickname = Directory Server CA certificate pki_ds_secure_connection_ca_pem_file = /etc/ipa/ca.crt pki_enable_proxy = True pki_existing = False pki_external = False pki_external_pkcs12_password = pki_external_pkcs12_path = pki_external_step_two = False pki_group = pkiuser pki_hostname = master.ufreeipa.test pki_hsm_enable = False pki_hsm_libfile = pki_hsm_modulename = pki_import_admin_cert = False pki_instance_configuration_path = /etc/pki/pki-tomcat pki_instance_name = pki-tomcat pki_issuing_ca = https://master.ufreeipa.test:443 pki_issuing_ca_hostname = master.ufreeipa.test pki_issuing_ca_https_port = 443 pki_issuing_ca_uri = https://master.ufreeipa.test:443 pki_master_crl_enable = True pki_ocsp_signing_key_algorithm = SHA256withRSA pki_ocsp_signing_key_size = 2048 pki_ocsp_signing_key_type = rsa pki_ocsp_signing_nickname = ocspSigningCert cert-pki-ca pki_ocsp_signing_signing_algorithm = SHA256withRSA pki_ocsp_signing_subject_dn = cn=OCSP Subsystem,O=UFREEIPA.TEST pki_ocsp_signing_token = internal pki_pkcs12_password = pki_pkcs12_path = pki_profiles_in_ldap = True pki_random_serial_numbers_enable = True pki_replica_number_range_end = 100 pki_replica_number_range_start = 1 pki_replication_password = pki_request_id_generator = random pki_request_number_range_end = 10000000 pki_request_number_range_start = 1 pki_san_for_server_cert = pki_san_inject = False pki_security_domain_hostname = master.ufreeipa.test pki_security_domain_https_port = 443 pki_security_domain_name = IPA pki_security_domain_password = XXXXXXXX pki_security_domain_user = admin pki_self_signed_token = internal pki_serial_number_range_end = 10000000 pki_serial_number_range_start = 1 pki_server_database_password = XXXXXXXX pki_share_db = False pki_share_dbuser_dn = uid=pkidbuser,ou=people,o=ipaca pki_skip_configuration = False pki_skip_ds_verify = False pki_skip_installation = False pki_skip_sd_verify = False pki_sslserver_key_algorithm = SHA256withRSA pki_sslserver_key_size = 2048 pki_sslserver_key_type = rsa pki_sslserver_nickname = Server-Cert cert-pki-ca pki_sslserver_subject_dn = cn=master.ufreeipa.test,O=UFREEIPA.TEST pki_sslserver_token = internal pki_status_request_timeout = 15 pki_subordinate = False pki_subordinate_create_new_security_domain = False pki_subsystem = CA pki_subsystem_key_algorithm = SHA256withRSA pki_subsystem_key_size = 2048 pki_subsystem_key_type = rsa pki_subsystem_nickname = subsystemCert cert-pki-ca pki_subsystem_subject_dn = cn=CA Subsystem,O=UFREEIPA.TEST pki_subsystem_token = internal pki_subsystem_type = ca pki_token_name = internal pki_user = pkiuser 2025-05-07T18:02:38Z DEBUG Starting external process 2025-05-07T18:02:38Z DEBUG args=['/usr/sbin/pkispawn', '-s', 'CA', '-f', '/tmp/tmpr1fhan9i', '--debug', '--log-file', '/var/log/pki/pki-ca-spawn.20250507180238.log'] 2025-05-07T18:05:15Z DEBUG Process finished, return code=0 2025-05-07T18:05:15Z DEBUG stdout=Relabeled /var/lib/pki/pki-tomcat from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/bin from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/conf from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/logs from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/lib from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/common from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/common/lib from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/temp from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/work from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/alias from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/ca from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/ca/registry from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/ca/conf from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/ca/logs from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/ca/alias from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/ca/emails from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/lib/pki/pki-tomcat/ca/profiles from unconfined_u:object_r:var_lib_t:s0 to unconfined_u:object_r:pki_tomcat_var_lib_t:s0 Relabeled /var/log/pki/pki-tomcat from unconfined_u:object_r:pki_log_t:s0 to unconfined_u:object_r:pki_tomcat_log_t:s0 Relabeled /var/log/pki/pki-tomcat/ca from unconfined_u:object_r:pki_log_t:s0 to unconfined_u:object_r:pki_tomcat_log_t:s0 Relabeled /var/log/pki/pki-tomcat/ca/archive from unconfined_u:object_r:pki_log_t:s0 to unconfined_u:object_r:pki_tomcat_log_t:s0 Relabeled /var/log/pki/pki-tomcat/ca/signedAudit from unconfined_u:object_r:pki_log_t:s0 to unconfined_u:object_r:pki_tomcat_log_t:s0 Relabeled /etc/pki/pki-tomcat from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/certs from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/server.xml from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/Catalina from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/Catalina/localhost from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/Catalina/localhost/rewrite.config from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/Catalina/localhost/ROOT.xml from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/Catalina/localhost/pki.xml from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/catalina.properties from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/context.xml from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/logging.properties from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/web.xml from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/password.conf from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/alias from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/alias/pkcs11.txt from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/alias/cert9.db from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/alias/key4.db from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/tomcat.conf from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_etc_rw_t:s0 Relabeled /etc/pki/pki-tomcat/ca from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/CS.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/registry.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/ExpiredUnpublishJob from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/ExpiredUnpublishJobItem from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/certIssued_CA from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/certIssued_CA.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/certIssued_RA from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/certIssued_RA.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/certRequestRejected.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/certRevoked_CA from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/certRevoked_CA.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/certRevoked_RA from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/certRevoked_RA.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/euJob1.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/euJob1Item.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/publishCerts.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/publishCertsItem.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/reqInQueue_CA from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/reqInQueue_CA.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/reqInQueue_RA from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/reqInQueue_RA.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/riq1Item.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/riq1Summary.html from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/rnJob1.txt from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/rnJob1Item.txt from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/emails/rnJob1Summary.txt from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/AdminCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/DomainController.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/ECAdminCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/acmeServerCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caAdminCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caAgentFileSigning.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caAgentServerCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caAuditSigningCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCACert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCECUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCECserverCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCECserverCertWithCRLDP.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCECsubsystemCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCauditSigningCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCcaCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCcaIssuanceProtectionCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCkraStorageCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCkraTransportCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCocspCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCserverCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCserverCertWithCRLDP.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCMCsubsystemCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caCrossSignedCACert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caDirBasedDualCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caDirPinUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caDirUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caDirUserRenewal.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caDualCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caDualRAuserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECAdminCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECAgentServerCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECDirPinUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECDirUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECDualCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECFullCMCSharedTokenCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECFullCMCUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECFullCMCUserSignedCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECInternalAuthServerCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECInternalAuthSubsystemCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECServerCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECServerCertWithCRLDP.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECServerCertWithSCT.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECSimpleCMCUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECSubsystemCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caECUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caEncECUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caEncUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caFullCMCSharedTokenCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caFullCMCUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caFullCMCUserSignedCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caIPAserviceCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caInstallCACert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthAuditSigningCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthDRMstorageCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthOCSPCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthServerCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthSubsystemCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthTransportCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caJarSigningCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caManualRenewal.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caOCSPCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caOtherCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caRACert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caRARouterCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caRAagentCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caRAserverCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caRouterCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caSSLClientSelfRenewal.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caServerCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caServerCertWithCRLDP.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caServerCertWithSCT.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caServerKeygen_DirUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caServerKeygen_UserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caSignedLogCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caSigningECUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caSigningUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caSimpleCMCUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caStorageCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caSubsystemCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTPSCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTempTokenDeviceKeyEnrollment.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTempTokenUserEncryptionKeyEnrollment.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTempTokenUserSigningKeyEnrollment.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTokenDeviceKeyEnrollment.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTokenMSLoginEnrollment.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserAuthKeyRenewal.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserDelegateAuthKeyEnrollment.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserDelegateSigningKeyEnrollment.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserEncryptionKeyEnrollment.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserEncryptionKeyRenewal.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserSigningKeyEnrollment.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserSigningKeyRenewal.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caTransportCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caUUIDdeviceCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caUserCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/caUserSMIMEcapCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/profiles/ca/estServiceCert.cfg from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/flatfile.txt from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/adminCert.profile from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/caAuditSigningCert.profile from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/caCert.profile from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/caOCSPCert.profile from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/serverCert.profile from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/subsystemCert.profile from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 Relabeled /etc/pki/pki-tomcat/ca/proxy.conf from unconfined_u:object_r:cert_t:s0 to unconfined_u:object_r:pki_tomcat_cert_t:s0 --------------- Export complete --------------- --------------- Export complete --------------- Loading deployment configuration from /tmp/tmpr1fhan9i. Installation log: /var/log/pki/pki-ca-spawn.20250507180238.log Installing CA into /var/lib/pki/pki-tomcat. ========================================================================== INSTALLATION SUMMARY ========================================================================== Administrator's username: admin Administrator's PKCS #12 file: /root/ca-agent.p12 To check the status of the subsystem: systemctl status pki-tomcatd@pki-tomcat.service To restart the subsystem: systemctl restart pki-tomcatd@pki-tomcat.service The URL for the subsystem is: https://master.ufreeipa.test:8443/ca PKI instances will be enabled upon system boot ========================================================================== 2025-05-07T18:05:15Z DEBUG stderr=WARNING: The 'pki_existing' in [CA] is no longer used. This parameter can be safely removed. WARNING: The 'pki_ds_hostname' in [CA] has been deprecated. Use 'pki_ds_url' instead. WARNING: The 'pki_ds_ldap_port' in [CA] has been deprecated. Use 'pki_ds_url' instead. WARNING: The 'pki_ds_ldaps_port' in [CA] has been deprecated. Use 'pki_ds_url' instead. WARNING: The 'pki_ds_secure_connection' in [CA] has been deprecated. Use 'pki_ds_url' instead. DEBUG: ===================================================== DISPLAY CONTENTS OF PKI MASTER DICTIONARY ===================================================== DEBUG: { 0: None, 'CATALINA_HOME': '/usr/share/tomcat', 'JAVA_HOME': '/usr/lib/jvm/jre-21-openjdk', '__name__': 'PKI Master Dictionary', 'application_version': '11.6.0', 'home_dir': '/root', 'java_home': '/usr/lib/jvm/jre-21-openjdk', 'nss_default_db_type': 'sql', 'pki_admin_cert_file': '/root/.dogtag/pki-tomcat/ca_admin.cert', 'pki_admin_cert_request_type': 'pkcs10', 'pki_admin_dualkey': 'False', 'pki_admin_email': 'root@localhost', 'pki_admin_key_algorithm': 'SHA256withRSA', 'pki_admin_key_size': '2048', 'pki_admin_key_type': 'rsa', 'pki_admin_keysize': '2048', 'pki_admin_name': 'admin', 'pki_admin_nickname': 'ipa-ca-agent', 'pki_admin_password': 'XXXXXXXX', 'pki_admin_profile_id': 'caAdminCert', 'pki_admin_setup': 'True', 'pki_admin_subject_dn': 'cn=ipa-ca-agent,O=UFREEIPA.TEST', 'pki_admin_uid': 'admin', 'pki_ajp_host': 'localhost4', 'pki_ajp_host_ipv4': '127.0.0.1', 'pki_ajp_host_ipv6': '::1', 'pki_ajp_port': '8009', 'pki_ajp_secret': '5VsZxV4lJeXZbe1aTK1wha4m29Sbfei1qVJzKkasTSZk', 'pki_architecture': 64, 'pki_audit_group': 'pkiaudit', 'pki_audit_signing_cert_path': '', 'pki_audit_signing_csr_path': '', 'pki_audit_signing_key_algorithm': 'SHA256withRSA', 'pki_audit_signing_key_size': '2048', 'pki_audit_signing_key_type': 'rsa', 'pki_audit_signing_nickname': 'auditSigningCert cert-pki-ca', 'pki_audit_signing_opFlags': '', 'pki_audit_signing_opFlagsMask': '', 'pki_audit_signing_signing_algorithm': 'SHA256withRSA', 'pki_audit_signing_subject_dn': 'cn=CA Audit,O=UFREEIPA.TEST', 'pki_audit_signing_token': 'internal', 'pki_backup_file': '', 'pki_backup_keys': 'True', 'pki_backup_password': 'XXXXXXXX', 'pki_ca_hostname': 'master.ufreeipa.test', 'pki_ca_port': '443', 'pki_ca_signing_cert_path': '', 'pki_ca_signing_csr_path': '', 'pki_ca_signing_key_algorithm': 'SHA256withRSA', 'pki_ca_signing_key_size': '3072', 'pki_ca_signing_key_type': 'rsa', 'pki_ca_signing_nickname': 'caSigningCert cert-pki-ca', 'pki_ca_signing_opFlags': '', 'pki_ca_signing_opFlagsMask': '', 'pki_ca_signing_record_create': 'True', 'pki_ca_signing_serial_number': '1', 'pki_ca_signing_signing_algorithm': 'SHA256withRSA', 'pki_ca_signing_subject_dn': 'CN=Certificate Authority,O=UFREEIPA.TEST', 'pki_ca_signing_token': 'internal', 'pki_ca_starting_crl_number': '0', 'pki_cert_chain_nickname': 'caSigningCert External CA', 'pki_cert_chain_path': '', 'pki_cert_id_generator': 'random', 'pki_cert_id_length': '128', 'pki_certificate_timestamp': '2025-05-07 18:02:38', 'pki_client_admin_cert': '/root/.dogtag/pki-tomcat/ca_admin.cert', 'pki_client_admin_cert_p12': '/root/ca-agent.p12', 'pki_client_database_dir': '/root/.dogtag/pki-tomcat/ca/alias', 'pki_client_database_password': 'XXXXXXXX', 'pki_client_database_purge': 'True', 'pki_client_dir': '/root/.dogtag/pki-tomcat', 'pki_client_password_conf': '/root/.dogtag/pki-tomcat/ca/password.conf', 'pki_client_pkcs12_password': 'XXXXXXXX', 'pki_client_pkcs12_password_conf': '/root/.dogtag/pki-tomcat/ca/pkcs12_password.conf', 'pki_client_subsystem_dir': '/root/.dogtag/pki-tomcat/ca', 'pki_clone': 'False', 'pki_clone_pkcs12_password': 'XXXXXXXX', 'pki_clone_pkcs12_path': '', 'pki_clone_reindex_data': 'False', 'pki_clone_replicate_schema': 'True', 'pki_clone_replication_clone_port': '', 'pki_clone_replication_master_port': '', 'pki_clone_replication_security': 'None', 'pki_clone_setup_replication': 'True', 'pki_clone_uri': 'https://master.ufreeipa.test:8443', 'pki_configuration_path': '/etc/pki', 'pki_default_ocsp_uri': 'http://ipa-ca.ufreeipa.test/ca/ocsp', 'pki_deployed_instance_name': None, 'pki_deployment_executable': 'pkispawn.py', 'pki_dns_domainname': 'ufreeipa.test', 'pki_ds_base_dn': 'o=ipaca', 'pki_ds_bind_dn': 'cn=Directory Manager', 'pki_ds_create_new_db': 'True', 'pki_ds_database': 'ipaca', 'pki_ds_hostname': 'master.ufreeipa.test', 'pki_ds_ldap_port': '389', 'pki_ds_ldaps_port': '636', 'pki_ds_password': 'XXXXXXXX', 'pki_ds_remove_data': 'True', 'pki_ds_secure_connection': 'False', 'pki_ds_secure_connection_ca_nickname': 'Directory Server CA certificate', 'pki_ds_secure_connection_ca_pem_file': '/etc/ipa/ca.crt', 'pki_ds_setup': 'True', 'pki_enable_access_log': 'True', 'pki_enable_java_debugger': 'False', 'pki_enable_on_system_boot': 'True', 'pki_enable_proxy': 'True', 'pki_existing': 'False', 'pki_external': 'False', 'pki_external_ca_cert_chain_nickname': 'caSigningCert External CA', 'pki_external_ca_cert_chain_path': '', 'pki_external_ca_cert_path': '', 'pki_external_csr_path': '', 'pki_external_pkcs12_password': 'XXXXXXXX', 'pki_external_pkcs12_path': '', 'pki_external_step_two': 'False', 'pki_group': 'pkiuser', 'pki_hostname': 'master.ufreeipa.test', 'pki_hsm_enable': 'False', 'pki_hsm_libfile': '', 'pki_hsm_modulename': '', 'pki_http_enable': 'True', 'pki_http_port': '8080', 'pki_https_port': '8443', 'pki_import_admin_cert': 'False', 'pki_import_system_certs': 'True', 'pki_install_time': 'Wed May 7 18:02:38 2025', 'pki_instance_configuration_path': '/etc/pki/pki-tomcat', 'pki_instance_name': 'pki-tomcat', 'pki_instance_path': '/var/lib/pki/pki-tomcat', 'pki_issuing_ca': 'https://master.ufreeipa.test:443', 'pki_issuing_ca_hostname': 'master.ufreeipa.test', 'pki_issuing_ca_https_port': '443', 'pki_issuing_ca_uri': 'https://master.ufreeipa.test:443', 'pki_master_crl_enable': 'True', 'pki_master_hostname': 'master.ufreeipa.test', 'pki_master_https_port': '8443', 'pki_ocsp_signing_cert_path': '', 'pki_ocsp_signing_csr_path': '', 'pki_ocsp_signing_key_algorithm': 'SHA256withRSA', 'pki_ocsp_signing_key_size': '2048', 'pki_ocsp_signing_key_type': 'rsa', 'pki_ocsp_signing_nickname': 'ocspSigningCert cert-pki-ca', 'pki_ocsp_signing_opFlags': '', 'pki_ocsp_signing_opFlagsMask': '', 'pki_ocsp_signing_signing_algorithm': 'SHA256withRSA', 'pki_ocsp_signing_subject_dn': 'cn=OCSP Subsystem,O=UFREEIPA.TEST', 'pki_ocsp_signing_token': 'internal', 'pki_pin': 'XXXXXXXX', 'pki_pkcs12_password': 'XXXXXXXX', 'pki_pkcs12_path': '', 'pki_profiles_in_ldap': 'True', 'pki_proxy_http_port': '80', 'pki_proxy_https_port': '443', 'pki_random_ajp_secret': 'GepPbqA1it4m4gunZ1fjGa6Q8', 'pki_random_serial_numbers_enable': 'True', 'pki_registry_enable': 'True', 'pki_replica_number_range_end': '100', 'pki_replica_number_range_start': '1', 'pki_replication_password': 'XXXXXXXX', 'pki_req_ext_add': 'False', 'pki_req_ext_critical': 'False', 'pki_req_ext_data': '', 'pki_req_ext_oid': '', 'pki_request_id_generator': 'random', 'pki_request_id_length': '128', 'pki_request_number_range_end': '10000000', 'pki_request_number_range_increment': '', 'pki_request_number_range_minimum': '', 'pki_request_number_range_start': '1', 'pki_request_number_range_transfer': '', 'pki_san_for_server_cert': '', 'pki_san_inject': 'False', 'pki_security_domain_hostname': 'master.ufreeipa.test', 'pki_security_domain_https_port': '443', 'pki_security_domain_name': 'IPA', 'pki_security_domain_password': 'XXXXXXXX', 'pki_security_domain_setup': 'True', 'pki_security_domain_type': 'new', 'pki_security_domain_uri': 'https://master.ufreeipa.test:443', 'pki_security_domain_user': 'admin', 'pki_security_manager': 'true', 'pki_self_signed_nickname': 'temp Server-Cert cert-pki-ca', 'pki_self_signed_token': 'internal', 'pki_serial_number_range_end': '10000000', 'pki_serial_number_range_increment': '', 'pki_serial_number_range_minimum': '', 'pki_serial_number_range_start': '1', 'pki_serial_number_range_transfer': '', 'pki_server_database_password': 'XXXXXXXX', 'pki_server_external_certs_path': '', 'pki_server_pkcs12_password': 'XXXXXXXX', 'pki_server_pkcs12_path': '', 'pki_share_db': 'False', 'pki_share_dbuser_dn': 'uid=pkidbuser,ou=people,o=ipaca', 'pki_skip_configuration': 'False', 'pki_skip_ds_verify': 'False', 'pki_skip_installation': 'False', 'pki_skip_sd_verify': 'False', 'pki_ssl_server_key_algorithm': 'SHA256withRSA', 'pki_ssl_server_key_size': '2048', 'pki_ssl_server_key_type': 'rsa', 'pki_ssl_server_nickname': 'Server-Cert cert-pki-tomcat', 'pki_ssl_server_subject_dn': 'cn=master.ufreeipa.test,ou=pki-tomcat,o=IPA', 'pki_ssl_server_token': '', 'pki_sslserver_cert_path': '', 'pki_sslserver_csr_path': '', 'pki_sslserver_key_algorithm': 'SHA256withRSA', 'pki_sslserver_key_size': '2048', 'pki_sslserver_key_type': 'rsa', 'pki_sslserver_nickname': 'Server-Cert cert-pki-ca', 'pki_sslserver_opFlags': '', 'pki_sslserver_opFlagsMask': '', 'pki_sslserver_signing_algorithm': 'SHA256withRSA', 'pki_sslserver_subject_dn': 'cn=master.ufreeipa.test,O=UFREEIPA.TEST', 'pki_sslserver_token': 'internal', 'pki_standalone': 'false', 'pki_status_request_timeout': '15', 'pki_storage_token': 'internal', 'pki_subordinate': 'False', 'pki_subordinate_create_new_security_domain': 'False', 'pki_subordinate_security_domain_name': 'ufreeipa.test Subordinate ' 'Security Domain', 'pki_subsystem': 'CA', 'pki_subsystem_cert_path': '', 'pki_subsystem_csr_path': '', 'pki_subsystem_key_algorithm': 'SHA256withRSA', 'pki_subsystem_key_size': '2048', 'pki_subsystem_key_type': 'rsa', 'pki_subsystem_name': 'CA master.ufreeipa.test 8443', 'pki_subsystem_nickname': 'subsystemCert cert-pki-ca', 'pki_subsystem_opFlags': '', 'pki_subsystem_opFlagsMask': '', 'pki_subsystem_signing_algorithm': 'SHA256withRSA', 'pki_subsystem_subject_dn': 'cn=CA Subsystem,O=UFREEIPA.TEST', 'pki_subsystem_token': 'internal', 'pki_subsystem_type': 'ca', 'pki_systemd_service_create': 'True', 'pki_timestamp': '20250507180238', 'pki_token_name': 'internal', 'pki_token_password': 'XXXXXXXX', 'pki_tomcat_bin_path': '/usr/share/tomcat/bin', 'pki_tomcat_lib_path': '/usr/share/tomcat/lib', 'pki_tomcat_server_port': '8005', 'pki_transport_token': 'internal', 'pki_use_oaep_rsa_keywrap': 'False', 'pki_use_pss_rsa_signing_algorithm': 'False', 'pki_user': 'pkiuser', 'pki_user_deployment_cfg': '/tmp/tmpr1fhan9i', 'sensitive_parameters': '\n' 'pki_admin_password\n' 'pki_backup_password\n' 'pki_client_database_password\n' 'pki_client_pin\n' 'pki_client_pkcs12_password\n' 'pki_clone_pkcs12_password\n' 'pki_ds_password\n' 'pki_external_pkcs12_password\n' 'pki_pkcs12_password\n' 'pki_one_time_pin\n' 'pki_pin\n' 'pki_replication_password\n' 'pki_security_domain_password\n' 'pki_server_database_password\n' 'pki_server_pkcs12_password\n' 'pki_token_password\n' 'acme_database_bind_password\n' 'acme_database_password\n' 'acme_issuer_password\n' 'acme_realm_bind_password\n' 'acme_realm_password\n' 'est_realm_bind_password\n' 'est_realm_password\n' 'est_ca_password'} INFO: Loading instance type: pki-tomcatd INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading external certs from /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: File does not exist: /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: Connecting to LDAP server at ldap://master.ufreeipa.test:389 INFO: Connecting to LDAP server at ldap://master.ufreeipa.test:389 INFO: BEGIN spawning CA subsystem in pki-tomcat instance INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading external certs from /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: File does not exist: /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: Reusing pkiuser group (GID: 17) INFO: Reusing pkiuser user (UID: 17) DEBUG: Retrieving UID for 'pkiuser' DEBUG: UID of 'pkiuser' is 17 DEBUG: Retrieving GID for 'pkiuser' DEBUG: GID of 'pkiuser' is 17 INFO: Initialization INFO: Setting up infrastructure INFO: Preparing pki-tomcat instance INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading external certs from /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: File does not exist: /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: Creating /var/lib/pki/pki-tomcat DEBUG: Command: mkdir /var/lib/pki/pki-tomcat INFO: Linking /var/lib/pki/pki-tomcat/bin to /usr/share/tomcat/bin DEBUG: Command: ln -s /usr/share/tomcat/bin /var/lib/pki/pki-tomcat/bin INFO: Creating /etc/pki/pki-tomcat DEBUG: Command: mkdir /etc/pki/pki-tomcat INFO: Linking /var/lib/pki/pki-tomcat/conf to /etc/pki/pki-tomcat DEBUG: Command: ln -s /etc/pki/pki-tomcat /var/lib/pki/pki-tomcat/conf INFO: Creating /var/log/pki/pki-tomcat DEBUG: Command: mkdir /var/log/pki/pki-tomcat INFO: Linking /var/lib/pki/pki-tomcat/logs to /var/log/pki/pki-tomcat DEBUG: Command: ln -s /var/log/pki/pki-tomcat /var/lib/pki/pki-tomcat/logs INFO: Linking /var/lib/pki/pki-tomcat/lib to /usr/share/pki/server/lib DEBUG: Command: ln -s /usr/share/pki/server/lib /var/lib/pki/pki-tomcat/lib INFO: Creating /var/lib/pki/pki-tomcat/common DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/common INFO: Linking /var/lib/pki/pki-tomcat/common/lib to /usr/share/pki/server/common/lib DEBUG: Command: ln -s /usr/share/pki/server/common/lib /var/lib/pki/pki-tomcat/common/lib INFO: Creating /var/lib/pki/pki-tomcat/temp DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/temp INFO: Creating /var/lib/pki/pki-tomcat/work DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/work INFO: Creating /var/lib/pki/pki-tomcat/conf/certs DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/conf/certs INFO: Copying /etc/tomcat/server.xml to /var/lib/pki/pki-tomcat/conf/server.xml DEBUG: Command: cp /etc/tomcat/server.xml /var/lib/pki/pki-tomcat/conf/server.xml INFO: Removing LockOutRealm INFO: Removing UserDatabase INFO: Updating AccessLogValve INFO: Configuring Tomcat admin port INFO: Removing AprLifecycleListener INFO: Adding PKIListener INFO: Configuring HTTP connector INFO: Adding HTTPS connector INFO: Adding SSL host configuration INFO: Adding SSL certificate configuration INFO: Adding RewriteValve INFO: Creating /var/lib/pki/pki-tomcat/conf/Catalina DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/conf/Catalina INFO: Creating /var/lib/pki/pki-tomcat/conf/Catalina/localhost DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/conf/Catalina/localhost INFO: Linking /var/lib/pki/pki-tomcat/conf/Catalina/localhost/rewrite.config to /usr/share/pki/server/conf/Catalina/localhost/rewrite.config DEBUG: Command: ln -s /usr/share/pki/server/conf/Catalina/localhost/rewrite.config /var/lib/pki/pki-tomcat/conf/Catalina/localhost/rewrite.config INFO: Adding AJP connector for IPv4 INFO: Adding AJP connector for IPv6 INFO: Updating AccessLogValve INFO: Linking /var/lib/pki/pki-tomcat/conf/catalina.properties to /usr/share/pki/server/conf/catalina.properties DEBUG: Command: ln -s /usr/share/pki/server/conf/catalina.properties /var/lib/pki/pki-tomcat/conf/catalina.properties INFO: Linking /var/lib/pki/pki-tomcat/conf/context.xml to /etc/tomcat/context.xml DEBUG: Command: ln -s /etc/tomcat/context.xml /var/lib/pki/pki-tomcat/conf/context.xml INFO: Linking /var/lib/pki/pki-tomcat/conf/logging.properties to /usr/share/pki/server/conf/logging.properties DEBUG: Command: ln -s /usr/share/pki/server/conf/logging.properties /var/lib/pki/pki-tomcat/conf/logging.properties INFO: Linking /var/lib/pki/pki-tomcat/conf/web.xml to /etc/tomcat/web.xml DEBUG: Command: ln -s /etc/tomcat/web.xml /var/lib/pki/pki-tomcat/conf/web.xml INFO: Using specified server NSS database password INFO: Using specified internal database password INFO: Generating random replication manager password INFO: Creating /var/lib/pki/pki-tomcat/conf/password.conf INFO: Creating /var/lib/pki/pki-tomcat/conf/alias DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/conf/alias INFO: Creating NSS database: /var/lib/pki/pki-tomcat/conf/alias DEBUG: Command: certutil -N -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpkvkjitkt/internal_password.txt INFO: Linking /var/lib/pki/pki-tomcat/alias to /var/lib/pki/pki-tomcat/conf/alias DEBUG: Command: ln -s /var/lib/pki/pki-tomcat/conf/alias /var/lib/pki/pki-tomcat/alias INFO: Creating /etc/sysconfig/pki-tomcat DEBUG: Command: cp /usr/share/pki/server/conf/tomcat.conf /etc/sysconfig/pki-tomcat INFO: Creating /var/lib/pki/pki-tomcat/conf/tomcat.conf DEBUG: Command: cp /usr/share/pki/server/conf/tomcat.conf /var/lib/pki/pki-tomcat/conf/tomcat.conf INFO: Deploying ROOT web application INFO: Creating /var/lib/pki/pki-tomcat/conf/Catalina/localhost/ROOT.xml INFO: Deploying pki web application INFO: Creating /var/lib/pki/pki-tomcat/conf/Catalina/localhost/pki.xml INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat DEBUG: Command: mkdir /etc/sysconfig/pki/tomcat/pki-tomcat INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: Command: cp /usr/share/pki/setup/pkidaemon_registry /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat INFO: Creating /etc/systemd/system/pki-tomcatd@pki-tomcat.service.d DEBUG: Command: mkdir /etc/systemd/system/pki-tomcatd@pki-tomcat.service.d DEBUG: Command: systemctl daemon-reload INFO: Linking /etc/systemd/system/pki-tomcatd.target.wants/pki-tomcatd@pki-tomcat.service to /lib/systemd/system/pki-tomcatd@.service DEBUG: Command: ln -s /lib/systemd/system/pki-tomcatd@.service /etc/systemd/system/pki-tomcatd.target.wants/pki-tomcatd@pki-tomcat.service INFO: Creating CA subsystem INFO: Creating /var/lib/pki/pki-tomcat/ca DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/ca INFO: Linking /var/lib/pki/pki-tomcat/ca/registry to /etc/sysconfig/pki/tomcat/pki-tomcat DEBUG: Command: ln -s /etc/sysconfig/pki/tomcat/pki-tomcat /var/lib/pki/pki-tomcat/ca/registry INFO: Creating /var/lib/pki/pki-tomcat/conf/ca DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/conf/ca INFO: Linking /var/lib/pki/pki-tomcat/ca/conf to /var/lib/pki/pki-tomcat/conf/ca DEBUG: Command: ln -s /var/lib/pki/pki-tomcat/conf/ca /var/lib/pki/pki-tomcat/ca/conf INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Copying /usr/share/pki/ca/conf/registry.cfg to /var/lib/pki/pki-tomcat/conf/ca/registry.cfg DEBUG: Command: cp /usr/share/pki/ca/conf/registry.cfg /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: Creating /var/lib/pki/pki-tomcat/logs/ca DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/logs/ca INFO: Linking /var/lib/pki/pki-tomcat/ca/logs to /var/lib/pki/pki-tomcat/logs/ca DEBUG: Command: ln -s /var/lib/pki/pki-tomcat/logs/ca /var/lib/pki/pki-tomcat/ca/logs INFO: Creating /var/lib/pki/pki-tomcat/logs/ca/archive DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/logs/ca/archive INFO: Creating /var/lib/pki/pki-tomcat/logs/ca/signedAudit DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/logs/ca/signedAudit INFO: Linking /var/lib/pki/pki-tomcat/ca/alias to /var/lib/pki/pki-tomcat/alias DEBUG: Command: ln -s /var/lib/pki/pki-tomcat/alias /var/lib/pki/pki-tomcat/ca/alias INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat/ca DEBUG: Command: mkdir /etc/sysconfig/pki/tomcat/pki-tomcat/ca INFO: Copying /usr/share/pki/server/etc/default.cfg to /etc/sysconfig/pki/tomcat/pki-tomcat/ca/default.cfg DEBUG: Command: cp /usr/share/pki/server/etc/default.cfg /etc/sysconfig/pki/tomcat/pki-tomcat/ca/default.cfg INFO: Creating /tmp/tmpq3y2xm_s/CS.cfg DEBUG: Command: cp /usr/share/pki/ca/conf/CS.cfg /tmp/tmpq3y2xm_s/CS.cfg INFO: Copying /usr/share/pki/ca/emails to /var/lib/pki/pki-tomcat/conf/ca/emails DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/conf/ca/emails DEBUG: Command: cp /usr/share/pki/ca/emails/ExpiredUnpublishJob /var/lib/pki/pki-tomcat/conf/ca/emails/ExpiredUnpublishJob DEBUG: Command: cp /usr/share/pki/ca/emails/ExpiredUnpublishJobItem /var/lib/pki/pki-tomcat/conf/ca/emails/ExpiredUnpublishJobItem DEBUG: Command: cp /usr/share/pki/ca/emails/certIssued_CA /var/lib/pki/pki-tomcat/conf/ca/emails/certIssued_CA DEBUG: Command: cp /usr/share/pki/ca/emails/certIssued_CA.html /var/lib/pki/pki-tomcat/conf/ca/emails/certIssued_CA.html DEBUG: Command: cp /usr/share/pki/ca/emails/certIssued_RA /var/lib/pki/pki-tomcat/conf/ca/emails/certIssued_RA DEBUG: Command: cp /usr/share/pki/ca/emails/certIssued_RA.html /var/lib/pki/pki-tomcat/conf/ca/emails/certIssued_RA.html DEBUG: Command: cp /usr/share/pki/ca/emails/certRequestRejected.html /var/lib/pki/pki-tomcat/conf/ca/emails/certRequestRejected.html DEBUG: Command: cp /usr/share/pki/ca/emails/certRevoked_CA /var/lib/pki/pki-tomcat/conf/ca/emails/certRevoked_CA DEBUG: Command: cp /usr/share/pki/ca/emails/certRevoked_CA.html /var/lib/pki/pki-tomcat/conf/ca/emails/certRevoked_CA.html DEBUG: Command: cp /usr/share/pki/ca/emails/certRevoked_RA /var/lib/pki/pki-tomcat/conf/ca/emails/certRevoked_RA DEBUG: Command: cp /usr/share/pki/ca/emails/certRevoked_RA.html /var/lib/pki/pki-tomcat/conf/ca/emails/certRevoked_RA.html DEBUG: Command: cp /usr/share/pki/ca/emails/euJob1.html /var/lib/pki/pki-tomcat/conf/ca/emails/euJob1.html DEBUG: Command: cp /usr/share/pki/ca/emails/euJob1Item.html /var/lib/pki/pki-tomcat/conf/ca/emails/euJob1Item.html DEBUG: Command: cp /usr/share/pki/ca/emails/publishCerts.html /var/lib/pki/pki-tomcat/conf/ca/emails/publishCerts.html DEBUG: Command: cp /usr/share/pki/ca/emails/publishCertsItem.html /var/lib/pki/pki-tomcat/conf/ca/emails/publishCertsItem.html DEBUG: Command: cp /usr/share/pki/ca/emails/reqInQueue_CA /var/lib/pki/pki-tomcat/conf/ca/emails/reqInQueue_CA DEBUG: Command: cp /usr/share/pki/ca/emails/reqInQueue_CA.html /var/lib/pki/pki-tomcat/conf/ca/emails/reqInQueue_CA.html DEBUG: Command: cp /usr/share/pki/ca/emails/reqInQueue_RA /var/lib/pki/pki-tomcat/conf/ca/emails/reqInQueue_RA DEBUG: Command: cp /usr/share/pki/ca/emails/reqInQueue_RA.html /var/lib/pki/pki-tomcat/conf/ca/emails/reqInQueue_RA.html DEBUG: Command: cp /usr/share/pki/ca/emails/riq1Item.html /var/lib/pki/pki-tomcat/conf/ca/emails/riq1Item.html DEBUG: Command: cp /usr/share/pki/ca/emails/riq1Summary.html /var/lib/pki/pki-tomcat/conf/ca/emails/riq1Summary.html DEBUG: Command: cp /usr/share/pki/ca/emails/rnJob1.txt /var/lib/pki/pki-tomcat/conf/ca/emails/rnJob1.txt DEBUG: Command: cp /usr/share/pki/ca/emails/rnJob1Item.txt /var/lib/pki/pki-tomcat/conf/ca/emails/rnJob1Item.txt DEBUG: Command: cp /usr/share/pki/ca/emails/rnJob1Summary.txt /var/lib/pki/pki-tomcat/conf/ca/emails/rnJob1Summary.txt INFO: Linking /var/lib/pki/pki-tomcat/ca/emails to /var/lib/pki/pki-tomcat/conf/ca/emails DEBUG: Command: ln -s /var/lib/pki/pki-tomcat/conf/ca/emails /var/lib/pki/pki-tomcat/ca/emails INFO: Copying /usr/share/pki/ca/profiles to /var/lib/pki/pki-tomcat/conf/ca/profiles DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/conf/ca/profiles DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/conf/ca/profiles/ca DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/AdminCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/AdminCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/DomainController.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/DomainController.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/ECAdminCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/ECAdminCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/acmeServerCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/acmeServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caAdminCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caAdminCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caAgentFileSigning.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caAgentFileSigning.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caAgentServerCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caAgentServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caAuditSigningCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caAuditSigningCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCACert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCACert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCECUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCECUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCECserverCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCECserverCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCECserverCertWithCRLDP.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCECserverCertWithCRLDP.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCECsubsystemCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCECsubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCauditSigningCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCauditSigningCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCcaCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCcaCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCcaIssuanceProtectionCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCcaIssuanceProtectionCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCkraStorageCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCkraStorageCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCkraTransportCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCkraTransportCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCocspCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCocspCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCserverCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCserverCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCserverCertWithCRLDP.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCserverCertWithCRLDP.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCsubsystemCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCMCsubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCrossSignedCACert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caCrossSignedCACert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDirBasedDualCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caDirBasedDualCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDirPinUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caDirPinUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDirUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caDirUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDirUserRenewal.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caDirUserRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDualCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caDualCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDualRAuserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caDualRAuserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECAdminCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECAdminCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECAgentServerCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECAgentServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECDirPinUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECDirPinUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECDirUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECDirUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECDualCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECDualCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECFullCMCSharedTokenCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECFullCMCSharedTokenCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECFullCMCUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECFullCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECFullCMCUserSignedCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECFullCMCUserSignedCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECInternalAuthServerCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECInternalAuthServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECInternalAuthSubsystemCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECInternalAuthSubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECServerCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECServerCertWithCRLDP.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECServerCertWithCRLDP.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECServerCertWithSCT.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECServerCertWithSCT.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECSimpleCMCUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECSimpleCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECSubsystemCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECSubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caECUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caEncECUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caEncECUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caEncUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caEncUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caFullCMCSharedTokenCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caFullCMCSharedTokenCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caFullCMCUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caFullCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caFullCMCUserSignedCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caFullCMCUserSignedCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caIPAserviceCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caIPAserviceCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInstallCACert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caInstallCACert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthAuditSigningCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caInternalAuthAuditSigningCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthDRMstorageCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caInternalAuthDRMstorageCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthOCSPCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caInternalAuthOCSPCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthServerCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caInternalAuthServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthSubsystemCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caInternalAuthSubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthTransportCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caInternalAuthTransportCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caJarSigningCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caJarSigningCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caManualRenewal.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caManualRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caOCSPCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caOCSPCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caOtherCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caOtherCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRACert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caRACert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRARouterCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caRARouterCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRAagentCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caRAagentCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRAserverCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caRAserverCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRouterCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caRouterCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSSLClientSelfRenewal.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caSSLClientSelfRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caServerCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caServerCertWithCRLDP.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caServerCertWithCRLDP.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caServerCertWithSCT.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caServerCertWithSCT.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caServerKeygen_DirUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caServerKeygen_DirUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caServerKeygen_UserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caServerKeygen_UserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSignedLogCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caSignedLogCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSigningECUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caSigningECUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSigningUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caSigningUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSimpleCMCUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caSimpleCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caStorageCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caStorageCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSubsystemCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caSubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTPSCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTPSCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTempTokenDeviceKeyEnrollment.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTempTokenDeviceKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTempTokenUserEncryptionKeyEnrollment.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTempTokenUserEncryptionKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTempTokenUserSigningKeyEnrollment.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTempTokenUserSigningKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenDeviceKeyEnrollment.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTokenDeviceKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenMSLoginEnrollment.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTokenMSLoginEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserAuthKeyRenewal.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTokenUserAuthKeyRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserDelegateAuthKeyEnrollment.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTokenUserDelegateAuthKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserDelegateSigningKeyEnrollment.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTokenUserDelegateSigningKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserEncryptionKeyEnrollment.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTokenUserEncryptionKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserEncryptionKeyRenewal.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTokenUserEncryptionKeyRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserSigningKeyEnrollment.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTokenUserSigningKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserSigningKeyRenewal.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTokenUserSigningKeyRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTransportCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caTransportCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caUUIDdeviceCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caUUIDdeviceCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caUserCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caUserSMIMEcapCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caUserSMIMEcapCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/estServiceCert.cfg /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/estServiceCert.cfg INFO: Linking /var/lib/pki/pki-tomcat/ca/profiles to /var/lib/pki/pki-tomcat/conf/ca/profiles DEBUG: Command: ln -s /var/lib/pki/pki-tomcat/conf/ca/profiles /var/lib/pki/pki-tomcat/ca/profiles INFO: Copying /usr/share/pki/ca/conf/flatfile.txt to /var/lib/pki/pki-tomcat/conf/ca/flatfile.txt DEBUG: Command: cp /usr/share/pki/ca/conf/flatfile.txt /var/lib/pki/pki-tomcat/conf/ca/flatfile.txt INFO: Copying /usr/share/pki/ca/conf/rsaAdminCert.profile to /var/lib/pki/pki-tomcat/conf/ca/adminCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/rsaAdminCert.profile /var/lib/pki/pki-tomcat/conf/ca/adminCert.profile INFO: Copying /usr/share/pki/ca/conf/caAuditSigningCert.profile to /var/lib/pki/pki-tomcat/conf/ca/caAuditSigningCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/caAuditSigningCert.profile /var/lib/pki/pki-tomcat/conf/ca/caAuditSigningCert.profile INFO: Copying /usr/share/pki/ca/conf/caCert.profile to /var/lib/pki/pki-tomcat/conf/ca/caCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/caCert.profile /var/lib/pki/pki-tomcat/conf/ca/caCert.profile INFO: Copying /usr/share/pki/ca/conf/caOCSPCert.profile to /var/lib/pki/pki-tomcat/conf/ca/caOCSPCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/caOCSPCert.profile /var/lib/pki/pki-tomcat/conf/ca/caOCSPCert.profile INFO: Copying /usr/share/pki/ca/conf/rsaServerCert.profile to /var/lib/pki/pki-tomcat/conf/ca/serverCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/rsaServerCert.profile /var/lib/pki/pki-tomcat/conf/ca/serverCert.profile INFO: Copying /usr/share/pki/ca/conf/rsaSubsystemCert.profile to /var/lib/pki/pki-tomcat/conf/ca/subsystemCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/rsaSubsystemCert.profile /var/lib/pki/pki-tomcat/conf/ca/subsystemCert.profile INFO: Creating /var/lib/pki/pki-tomcat/conf/ca/proxy.conf DEBUG: Command: cp /usr/share/pki/ca/conf/proxy.conf /var/lib/pki/pki-tomcat/conf/ca/proxy.conf INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /var/lib/pki/pki-tomcat/conf/tomcat.conf INFO: Loading password config: /var/lib/pki/pki-tomcat/conf/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Loading external certs from /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: File does not exist: /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: Enabling HTTP proxy INFO: Setting proxy.securePort to 443 INFO: Setting proxy.unsecurePort to 80 INFO: Setting subsystem.1.class to com.netscape.cmscore.profile.LDAPProfileSubsystem DEBUG: PKISubsystem.get_subsystem_cert(signing) DEBUG: PKISubsystem.get_cert_info(signing) INFO: Setting ca.signing.nickname to caSigningCert cert-pki-ca INFO: Setting ca.signing.tokenname to internal INFO: Setting ca.cert.signing.nickname to caSigningCert cert-pki-ca INFO: Setting ca.signing.defaultSigningAlgorithm to SHA256withRSA INFO: Setting ca.crl.MasterCRL.signingAlgorithm to SHA256withRSA DEBUG: PKISubsystem.get_subsystem_cert(ocsp_signing) DEBUG: PKISubsystem.get_cert_info(ocsp_signing) INFO: Setting ca.ocsp_signing.nickname to ocspSigningCert cert-pki-ca INFO: Setting ca.ocsp_signing.tokenname to internal INFO: Setting ca.cert.ocsp_signing.nickname to ocspSigningCert cert-pki-ca INFO: Setting ca.ocsp_signing.defaultSigningAlgorithm to SHA256withRSA DEBUG: PKISubsystem.get_subsystem_cert(sslserver) DEBUG: PKISubsystem.get_cert_info(sslserver) INFO: Setting ca.sslserver.nickname to Server-Cert cert-pki-ca INFO: Setting ca.sslserver.tokenname to internal INFO: Setting ca.cert.sslserver.nickname to Server-Cert cert-pki-ca DEBUG: PKISubsystem.get_subsystem_cert(subsystem) DEBUG: PKISubsystem.get_cert_info(subsystem) INFO: Setting ca.subsystem.nickname to subsystemCert cert-pki-ca INFO: Setting ca.subsystem.tokenname to internal INFO: Setting ca.cert.subsystem.nickname to subsystemCert cert-pki-ca DEBUG: PKISubsystem.get_subsystem_cert(audit_signing) DEBUG: PKISubsystem.get_cert_info(audit_signing) INFO: Setting ca.audit_signing.nickname to auditSigningCert cert-pki-ca INFO: Setting ca.audit_signing.tokenname to internal INFO: Setting ca.cert.audit_signing.nickname to auditSigningCert cert-pki-ca INFO: Setting ca.signing.certnickname to caSigningCert cert-pki-ca INFO: Setting ca.signing.cacertnickname to caSigningCert cert-pki-ca INFO: Setting ca.ocsp_signing.certnickname to ocspSigningCert cert-pki-ca INFO: Setting ca.ocsp_signing.cacertnickname to ocspSigningCert cert-pki-ca INFO: Setting log.instance.SignedAudit.signedAuditCertNickname to auditSigningCert cert-pki-ca INFO: Injecting SAN: False INFO: SSL server cert SAN: INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg DEBUG: Command: mkdir /root/.dogtag DEBUG: Command: mkdir /root/.dogtag/pki-tomcat DEBUG: Command: mkdir /root/.dogtag/pki-tomcat/ca INFO: Creating password file: /root/.dogtag/pki-tomcat/ca/password.conf INFO: Storing PKCS #12 password in /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf DEBUG: Command: mkdir /root/.dogtag/pki-tomcat/ca/alias DEBUG: Command: certutil -N -d /root/.dogtag/pki-tomcat/ca/alias -f /root/.dogtag/pki-tomcat/ca/password.conf INFO: Creating SELinux contexts DEBUG: Command: /usr/sbin/restorecon -R -v /var/lib/pki/pki-tomcat DEBUG: Command: /usr/sbin/restorecon -R -v /var/log/pki DEBUG: Command: /usr/sbin/restorecon -R -v /var/log/pki/pki-tomcat DEBUG: Command: /usr/sbin/restorecon -R -v /etc/pki/pki-tomcat INFO: Generating system keys INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /var/lib/pki/pki-tomcat/conf/tomcat.conf INFO: Loading password config: /var/lib/pki/pki-tomcat/conf/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Loading external certs from /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: File does not exist: /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: Fapolicy folder not found. Rule configuration skipped INFO: Configuring subsystem INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /var/lib/pki/pki-tomcat/conf/tomcat.conf INFO: Loading password config: /var/lib/pki/pki-tomcat/conf/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Loading external certs from /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: File does not exist: /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: Setting internaldb.ldapconn.secureConn to false INFO: Setting internaldb.ldapconn.host to master.ufreeipa.test INFO: Setting internaldb.ldapconn.port to 389 INFO: Setting internaldb.ldapauth.bindDN to cn=Directory Manager INFO: Setting internaldb.basedn to o=ipaca INFO: Setting internaldb.database to ipaca INFO: Setting dbs.request.id.generator to random INFO: Setting dbs.request.id.length to 128 INFO: Setting dbs.cert.id.generator to random INFO: Setting dbs.cert.id.length to 128 INFO: Setting dbs.beginReplicaNumber to 1 INFO: Setting dbs.endReplicaNumber to 100 INFO: Setting ca.defaultOcspUri to http://ipa-ca.ufreeipa.test/ca/ocsp INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg DEBUG: PKIDeployer.import_system_certs() DEBUG: import_system_cert DEBUG: import_system_cert DEBUG: import_system_cert DEBUG: import_system_cert DEBUG: import_system_cert INFO: Checking existing cert chain: caSigningCert External CA DEBUG: NSSDatabase.get_cert(caSigningCert External CA) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpmq0s5fi1/password.txt -n caSigningCert External CA -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: caSigningCert External CA : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: caSigningCert External CA INFO: Updating system certs INFO: Setting ca.signing.cacertnickname to caSigningCert cert-pki-ca INFO: Setting ca.signing.defaultSigningAlgorithm to SHA256withRSA INFO: Setting ca.ocsp_signing.defaultSigningAlgorithm to SHA256withRSA INFO: Setting ca.audit_signing.defaultSigningAlgorithm to SHA256withRSA INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg DEBUG: PKISubsystem.get_subsystem_cert(sslserver) DEBUG: PKISubsystem.get_cert_info(sslserver) DEBUG: PKISubsystem.get_nssdb_cert_info(sslserver) DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpyga9zoln/password.txt -n Server-Cert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: Server-Cert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: Server-Cert cert-pki-ca INFO: Updating /var/lib/pki/pki-tomcat/conf/serverCertNick.conf INFO: Updating serverCertNickFile in server.xml INFO: Creating new security domain INFO: Setting securitydomain.host to master.ufreeipa.test INFO: Setting securitydomain.httpport to 8080 INFO: Setting securitydomain.httpsadminport to 8443 INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: Removing existing database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-remove --force --debug INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemDBRemoveCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Removing database ipaca FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 INFO: Validating database ownership INFO: Validating database ipaca is owned by o=ipaca INFO: Deleting mapping entry cn="o=ipaca",cn=mapping tree, cn=config INFO: Deleting cn="o=ipaca",cn=mapping tree, cn=config INFO: Entry not found: cn="o=ipaca",cn=mapping tree, cn=config INFO: Deleting database entry cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Deleting cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Entry not found: cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Creating database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-create --debug INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemDBCreateCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Creating database ipaca FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 INFO: Adding cn=ipaca,cn=ldbm database,cn=plugins,cn=config INFO: Adding cn="o=ipaca",cn=mapping tree,cn=config INFO: Initializing database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-init --debug INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: CADBInitCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Initializing database ipaca for o=ipaca FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 INFO: Configuring DS server INFO: Importing /usr/share/pki/server/database/ds/config.ldif FINE: - database: ipaca FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-10983094136971161102.ldif INFO: Replacing nsslapd-maxbersize in cn=config INFO: Replacing nsslapd-pluginenabled in cn=USN,cn=plugins,cn=config INFO: Adding ou=csusers,cn=config INFO: Setting up PKI schema INFO: Importing /usr/share/pki/server/database/ds/schema.ldif INFO: Adding attributetypes: ( usertype-oid NAME 'usertype' DESC 'Distinguish whether the user is administrator, agent or subsystem.' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( userstate-oid NAME 'userstate' DESC 'Distinguish whether the user is administrator, agent or subsystem.' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( cmsuser-oid NAME 'cmsuser' DESC 'CMS User' SUP top STRUCTURAL MUST usertype MAY userstate X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( archivedBy-oid NAME 'archivedBy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( adminMessages-oid NAME 'adminMessages' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( algorithm-oid NAME 'algorithm' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( algorithmId-oid NAME 'algorithmId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( signingAlgorithmId-oid NAME 'signingAlgorithmId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( autoRenew-oid NAME 'autoRenew' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( certStatus-oid NAME 'certStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlName-oid NAME 'crlName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlSize-oid NAME 'crlSize' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( deltaSize-oid NAME 'deltaSize' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlNumber-oid NAME 'crlNumber' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( deltaNumber-oid NAME 'deltaNumber' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( firstUnsaved-oid NAME 'firstUnsaved' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlCache-oid NAME 'crlCache' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revokedCerts-oid NAME 'revokedCerts' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( unrevokedCerts-oid NAME 'unrevokedCerts' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( expiredCerts-oid NAME 'expiredCerts' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlExtensions-oid NAME 'crlExtensions' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfArchival-oid NAME 'dateOfArchival' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfRecovery-oid NAME 'dateOfRecovery' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfRevocation-oid NAME 'dateOfRevocation' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfCreate-oid NAME 'dateOfCreate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfModify-oid NAME 'dateOfModify' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( duration-oid NAME 'duration' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( extension-oid NAME 'extension' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( issuedBy-oid NAME 'issuedBy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( issueInfo-oid NAME 'issueInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( issuerName-oid NAME 'issuerName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( keySize-oid NAME 'keySize' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( clientId-oid NAME 'clientId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dataType-oid NAME 'dataType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( status-oid NAME 'status' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( keyState-oid NAME 'keyState' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( metaInfo-oid NAME 'metaInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( nextUpdate-oid NAME 'nextUpdate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( notAfter-oid NAME 'notAfter' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( notBefore-oid NAME 'notBefore' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( ownerName-oid NAME 'ownerName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( password-oid NAME 'password' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( p12Expiration-oid NAME 'p12Expiration' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( proofOfArchival-oid NAME 'proofOfArchival' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( publicKeyData-oid NAME 'publicKeyData' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( publicKeyFormat-oid NAME 'publicKeyFormat' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( privateKeyData-oid NAME 'privateKeyData' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestId-oid NAME 'requestId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestInfo-oid NAME 'requestInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestState-oid NAME 'requestState' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestResult-oid NAME 'requestResult' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestOwner-oid NAME 'requestOwner' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestAgentGroup-oid NAME 'requestAgentGroup' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestSourceId-oid NAME 'requestSourceId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestType-oid NAME 'requestType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestFlag-oid NAME 'requestFlag' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestError-oid NAME 'requestError' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( resourceACLS-oid NAME 'resourceACLS' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revInfo-oid NAME 'revInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revokedBy-oid NAME 'revokedBy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revokedOn-oid NAME 'revokedOn' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( serialno-oid NAME 'serialno' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( nextRange-oid NAME 'nextRange' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( publishingStatus-oid NAME 'publishingStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( beginRange-oid NAME 'beginRange' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( endRange-oid NAME 'endRange' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( subjectName-oid NAME 'subjectName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( sessionContext-oid NAME 'sessionContext' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( thisUpdate-oid NAME 'thisUpdate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transId-oid NAME 'transId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transStatus-oid NAME 'transStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transName-oid NAME 'transName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transOps-oid NAME 'transOps' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( userDN-oid NAME 'userDN' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( userMessages-oid NAME 'userMessages' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( version-oid NAME 'version' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( Clone-oid NAME 'Clone' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( DomainManager-oid NAME 'DomainManager' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecurePort-oid NAME 'SecurePort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecureAgentPort-oid NAME 'SecureAgentPort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecureAdminPort-oid NAME 'SecureAdminPort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecureEEClientAuthPort-oid NAME 'SecureEEClientAuthPort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( UnSecurePort-oid NAME 'UnSecurePort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SubsystemName-oid NAME 'SubsystemName' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( cmsUserGroup-oid NAME 'cmsUserGroup' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( realm-oid NAME 'realm' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( CertACLS-oid NAME 'CertACLS' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY resourceACLS X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( repository-oid NAME 'repository' DESC 'CMS defined class' SUP top STRUCTURAL MUST ou MAY ( serialno $ description $ nextRange $ publishingStatus ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( request-oid NAME 'request' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( requestId $ dateOfCreate $ dateOfModify $ requestState $ requestResult $ requestOwner $ requestAgentGroup $ requestSourceId $ requestType $ requestFlag $ requestError $ userMessages $ adminMessages $ realm ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( transaction-oid NAME 'transaction' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( transId $ description $ transName $ transStatus $ transOps ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( crlIssuingPointRecord-oid NAME 'crlIssuingPointRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ crlNumber $ crlSize $ thisUpdate $ nextUpdate $ deltaNumber $ deltaSize $ firstUnsaved $ certificateRevocationList $ deltaRevocationList $ crlCache $ revokedCerts $ unrevokedCerts $ expiredCerts $ cACertificate ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( certificateRecord-oid NAME 'certificateRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( serialno $ dateOfCreate $ dateOfModify $ certStatus $ autoRenew $ issueInfo $ metaInfo $ revInfo $ version $ duration $ notAfter $ notBefore $ algorithmId $ subjectName $ signingAlgorithmId $ userCertificate $ issuedBy $ revokedBy $ revokedOn $ extension $ publicKeyData $ issuerName ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( userDetails-oid NAME 'userDetails' DESC 'CMS defined class' SUP top STRUCTURAL MUST userDN MAY ( dateOfCreate $ dateOfModify $ password $ p12Expiration ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( keyRecord-oid NAME 'keyRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( serialno $ dateOfCreate $ dateOfModify $ keyState $ privateKeyData $ ownerName $ keySize $ metaInfo $ dateOfArchival $ dateOfRecovery $ algorithm $ publicKeyFormat $ publicKeyData $ archivedBy $ clientId $ dataType $ status $ realm ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiSecurityDomain-oid NAME 'pkiSecurityDomain' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( ou $ name ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiSecurityGroup-oid NAME 'pkiSecurityGroup' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiSubsystem-oid NAME 'pkiSubsystem' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( cn $ Host $ SecurePort $ SubsystemName $ Clone ) MAY ( DomainManager $ SecureAgentPort $ SecureAdminPort $SecureEEClientAuthPort $ UnSecurePort ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiRange-oid NAME 'pkiRange' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( cn $ beginRange $ endRange $ Host $ SecurePort ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( securityDomainSessionEntry-oid NAME 'securityDomainSessionEntry' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( cn $ host $ uid $ cmsUserGroup $ dateOfCreate ) X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfCreate-oid NAME 'dateOfCreate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfModify-oid NAME 'dateOfModify' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( modified-oid NAME 'modified' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenUserID-oid NAME 'tokenUserID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenStatus-oid NAME 'tokenStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenAppletID-oid NAME 'tokenAppletID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( keyInfo-oid NAME 'keyInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfResets-oid NAME 'numberOfResets' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfEnrollments-oid NAME 'numberOfEnrollments' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfRenewals-oid NAME 'numberOfRenewals' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfRecoveries-oid NAME 'numberOfRecoveries' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( allowPinReset-oid NAME 'allowPinReset' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( extensions-oid NAME 'extensions' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenOp-oid NAME 'tokenOp' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenID-oid NAME 'tokenID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenMsg-oid NAME 'tokenMsg' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenResult-oid NAME 'tokenResult' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenIP-oid NAME 'tokenIP' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenPolicy-oid NAME 'tokenPolicy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenIssuer-oid NAME 'tokenIssuer' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenSubject-oid NAME 'tokenSubject' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenSerial-oid NAME 'tokenSerial' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenOrigin-oid NAME 'tokenOrigin' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenType-oid NAME 'tokenType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenKeyType-oid NAME 'tokenKeyType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenReason-oid NAME 'tokenReason' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenNotBefore-oid NAME 'tokenNotBefore' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenNotAfter-oid NAME 'tokenNotAfter' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( profileID-oid NAME 'profileID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tokenRecord-oid NAME 'tokenRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ modified $ tokenReason $ tokenUserID $ tokenStatus $ tokenAppletID $ keyInfo $ tokenPolicy $ extensions $ numberOfResets $ numberOfEnrollments $ numberOfRenewals $ numberOfRecoveries $ userCertificate $ tokenType ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tokenActivity-oid NAME 'tokenActivity' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ tokenOp $ tokenIP $ tokenResult $ tokenID $ tokenUserID $ tokenMsg $ extensions $ tokenType ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tokenCert-oid NAME 'tokenCert' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ userCertificate $ tokenUserID $ tokenID $ tokenIssuer $ tokenOrigin $ tokenSubject $ tokenSerial $ tokenStatus $ tokenType $ tokenKeyType $ tokenNotBefore $ tokenNotAfter $ extensions ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tpsProfileID-oid NAME 'tpsProfileID' DESC 'CMS defined class' SUP top AUXILIARY MAY ( profileID ) X-ORIGIN 'user-defined' ) INFO: Adding attributetypes: ( classId-oid NAME 'classId' DESC 'Certificate profile class ID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( certProfileConfig-oid NAME 'certProfileConfig' DESC 'Certificate profile configuration' SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( certProfile-oid NAME 'certProfile' DESC 'Certificate profile' SUP top STRUCTURAL MUST cn MAY ( classId $ certProfileConfig ) X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityID-oid NAME 'authorityID' DESC 'Authority ID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityKeyNickname-oid NAME 'authorityKeyNickname' DESC 'Authority key nickname' SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN 'user-defined' ) INFO: Adding attributetypes: ( authorityParentID-oid NAME 'authorityParentID' DESC 'Authority Parent ID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityEnabled-oid NAME 'authorityEnabled' DESC 'Authority Enabled' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityDN-oid NAME 'authorityDN' DESC 'Authority DN' SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authoritySerial-oid NAME 'authoritySerial' DESC 'Authority certificate serial number' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityParentDN-oid NAME 'authorityParentDN' DESC 'Authority Parent DN' SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityKeyHost-oid NAME 'authorityKeyHost' DESC 'Authority Key Hosts' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( authority-oid NAME 'authority' DESC 'Certificate Authority' SUP top STRUCTURAL MUST ( cn $ authorityID $ authorityKeyNickname $ authorityEnabled $ authorityDN ) MAY ( authoritySerial $ authorityParentID $ authorityParentDN $ authorityKeyHost $ description ) X-ORIGIN 'user defined' ) INFO: Adding o=ipaca INFO: Creating container entries INFO: Importing /usr/share/pki/ca/database/ds/create.ldif FINE: - database: ipaca FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-4434002456787115389.ldif INFO: Adding ou=people,o=ipaca INFO: Adding ou=groups,o=ipaca INFO: Adding cn=Certificate Manager Agents,ou=groups,o=ipaca INFO: Adding cn=Registration Manager Agents,ou=groups,o=ipaca INFO: Adding cn=Subsystem Group, ou=groups, o=ipaca INFO: Adding cn=Trusted Managers,ou=groups,o=ipaca INFO: Adding cn=Administrators,ou=groups,o=ipaca INFO: Adding cn=Auditors,ou=groups,o=ipaca INFO: Adding cn=ClonedSubsystems,ou=groups,o=ipaca INFO: Adding cn=Security Domain Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise CA Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise KRA Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise OCSP Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise TKS Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise RA Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise TPS Administrators,ou=groups,o=ipaca INFO: Adding ou=requests,o=ipaca INFO: Adding cn=crossCerts,o=ipaca INFO: Adding ou=ca,o=ipaca INFO: Adding ou=certificateRepository,ou=ca,o=ipaca INFO: Adding ou=crlIssuingPoints,ou=ca,o=ipaca INFO: Adding ou=ca, ou=requests,o=ipaca INFO: Adding ou=replica,o=ipaca INFO: Adding ou=ranges,o=ipaca INFO: Adding ou=replica, ou=ranges,o=ipaca INFO: Adding ou=certificateProfiles,ou=ca,o=ipaca INFO: Adding ou=authorities,ou=ca,o=ipaca INFO: Setting up ACL INFO: Importing /usr/share/pki/ca/database/ds/acl.ldif FINE: - database: ipaca FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-6023563710455596794.ldif INFO: Adding cn=aclResources,o=ipaca DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-access-grant --debug uid=pkidbuser,ou=people,o=ipaca DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-index-add --debug INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemDBIndexAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 INFO: Creating indexes INFO: Importing /usr/share/pki/ca/database/ds/index.ldif FINE: - database: ipaca FINE: - instanceId: pki-tomcat FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-15464337734963098842.ldif INFO: Adding cn=revokedby,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=issuedby,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=publicKeyData,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=clientId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=dataType,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=status,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=description,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=serialno,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=metaInfo,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=certstatus,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requestid,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requesttype,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requeststate,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requestowner,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=notbefore,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=notafter,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=duration,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=dateOfCreate,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=revokedOn,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=archivedBy,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=ownername,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=issuername,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=subjectname,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requestsourceid,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=revInfo,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=extension,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeExpires,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeAccountId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeStatus,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeAuthorizationId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeIdentifier,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeCertificateId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeAuthorizationWildcard,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-vlv-add --debug INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemDBVLVAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 INFO: Add VLVs INFO: Importing /usr/share/pki/ca/database/ds/vlv.ldif FINE: - database: ipaca FINE: - instanceId: pki-tomcat FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-3898352310812105479.ldif INFO: Adding cn=allCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allInvalidCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allInValidCertsNotBefore-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allNonRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCaCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCertsNotAfter-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedOrRevokedExpiredCaCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedOrRevokedExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidCertsNotAfter-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidOrRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caAll-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceled-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caComplete-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPending-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejected-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allCerts-pki-tomcatIndex, cn=allCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allExpiredCerts-pki-tomcatIndex, cn=allExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allInvalidCerts-pki-tomcatIndex, cn=allInvalidCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allInValidCertsNotBefore-pki-tomcatIndex, cn=allInValidCertsNotBefore-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allNonRevokedCerts-pki-tomcatIndex, cn=allNonRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCaCerts-pki-tomcatIndex, cn=allRevokedCaCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCerts-pki-tomcatIndex, cn=allRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCertsNotAfter-pki-tomcatIndex, cn=allRevokedCertsNotAfter-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedExpiredCerts-pki-tomcatIndex, cn=allRevokedExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedOrRevokedExpiredCaCerts-pki-tomcatIndex, cn=allRevokedOrRevokedExpiredCaCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedOrRevokedExpiredCerts-pki-tomcatIndex, cn=allRevokedOrRevokedExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidCerts-pki-tomcatIndex, cn=allValidCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidCertsNotAfter-pki-tomcatIndex, cn=allValidCertsNotAfter-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidOrRevokedCerts-pki-tomcatIndex, cn=allValidOrRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caAll-pki-tomcatIndex, cn=caAll-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceled-pki-tomcatIndex, cn=caCanceled-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledEnrollment-pki-tomcatIndex, cn=caCanceledEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledRenewal-pki-tomcatIndex, cn=caCanceledRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledRevocation-pki-tomcatIndex, cn=caCanceledRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caComplete-pki-tomcatIndex, cn=caComplete-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteEnrollment-pki-tomcatIndex, cn=caCompleteEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteRenewal-pki-tomcatIndex, cn=caCompleteRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteRevocation-pki-tomcatIndex, cn=caCompleteRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caEnrollment-pki-tomcatIndex, cn=caEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPending-pki-tomcatIndex, cn=caPending-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingEnrollment-pki-tomcatIndex, cn=caPendingEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingRenewal-pki-tomcatIndex, cn=caPendingRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingRevocation-pki-tomcatIndex, cn=caPendingRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejected-pki-tomcatIndex, cn=caRejected-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedEnrollment-pki-tomcatIndex, cn=caRejectedEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedRenewal-pki-tomcatIndex, cn=caRejectedRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedRevocation-pki-tomcatIndex, cn=caRejectedRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRenewal-pki-tomcatIndex, cn=caRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRevocation-pki-tomcatIndex, cn=caRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-vlv-reindex --debug INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemDBVLVReindexCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 INFO: Reindex VLVs INFO: Importing /usr/share/pki/ca/database/ds/vlvtasks.ldif FINE: - database: ipaca FINE: - instanceId: pki-tomcat FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-46786077892292951.ldif INFO: Adding cn=index1160589769, cn=index, cn=tasks, cn=config INFO: Waiting for task cn=index1160589769, cn=index, cn=tasks, cn=config (1s) INFO: Getting cn=index1160589769, cn=index, cn=tasks, cn=config INFO: Waiting for task cn=index1160589769, cn=index, cn=tasks, cn=config (2s) INFO: Getting cn=index1160589769, cn=index, cn=tasks, cn=config INFO: Waiting for task cn=index1160589769, cn=index, cn=tasks, cn=config (3s) INFO: Getting cn=index1160589769, cn=index, cn=tasks, cn=config INFO: Task cn=index1160589769, cn=index, cn=tasks, cn=config complete DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-profile-import --input-folder /usr/share/pki/ca/profiles/ca --debug INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: PluginRegistry: Loading plugin registry from /var/lib/pki/pki-tomcat/conf/ca/registry.cfg FINE: PluginRegistry: profile: FINE: PluginRegistry: - caEnrollImpl FINE: PluginRegistry: Added plugin profile caEnrollImpl Generic Certificate Enrollment Profile Certificate Authority Generic Certificate Enrollment Profile com.netscape.cms.profile.common.CAEnrollProfile FINE: PluginRegistry: - caCACertEnrollImpl FINE: PluginRegistry: Added plugin profile caCACertEnrollImpl CA Certificate Enrollment Profile Certificate Authority CA Certificate Enrollment Profile com.netscape.cms.profile.common.CACertCAEnrollProfile FINE: PluginRegistry: - caServerCertEnrollImpl FINE: PluginRegistry: Added plugin profile caServerCertEnrollImpl Server Certificate Enrollment Profile Certificate Authority Server Certificate Enrollment Profile com.netscape.cms.profile.common.ServerCertCAEnrollProfile FINE: PluginRegistry: - caUserCertEnrollImpl FINE: PluginRegistry: Added plugin profile caUserCertEnrollImpl User Certificate Enrollment Profile Certificate Authority User Certificate Enrollment Profile com.netscape.cms.profile.common.UserCertCAEnrollProfile FINE: PluginRegistry: defaultPolicy: FINE: PluginRegistry: - noDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy noDefaultImpl No Default No Default com.netscape.cms.profile.def.NoDefault FINE: PluginRegistry: - genericExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy genericExtDefaultImpl Generic Extension Generic Extension com.netscape.cms.profile.def.GenericExtDefault FINE: PluginRegistry: - autoAssignDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy autoAssignDefaultImpl Auto Request Assignment Default Auto Request Assignment Default com.netscape.cms.profile.def.AutoAssignDefault FINE: PluginRegistry: - subjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectNameDefaultImpl Subject Name Default Subject Name Default com.netscape.cms.profile.def.SubjectNameDefault FINE: PluginRegistry: - validityDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy validityDefaultImpl Validity Default Validty Default com.netscape.cms.profile.def.ValidityDefault FINE: PluginRegistry: - randomizedValidityDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy randomizedValidityDefaultImpl Randomized Validity Default Randomized Validity Default com.netscape.cms.profile.def.RandomizedValidityDefault FINE: PluginRegistry: - caValidityDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy caValidityDefaultImpl CA Certificate Validity Default CA Certificate Validty Default com.netscape.cms.profile.def.CAValidityDefault FINE: PluginRegistry: - subjectKeyIdentifierExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectKeyIdentifierExtDefaultImpl Subject Key Identifier Default Subject Key Identifier Default com.netscape.cms.profile.def.SubjectKeyIdentifierExtDefault FINE: PluginRegistry: - authorityKeyIdentifierExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy authorityKeyIdentifierExtDefaultImpl Authority Key Identifier Extension Default Authority Key Identifier Extension Default com.netscape.cms.profile.def.AuthorityKeyIdentifierExtDefault FINE: PluginRegistry: - basicConstraintsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy basicConstraintsExtDefaultImpl Basic Constraints Extension Default Basic Constraints Extension Default com.netscape.cms.profile.def.BasicConstraintsExtDefault FINE: PluginRegistry: - keyUsageExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy keyUsageExtDefaultImpl Key Usage Extension Default Key Usage Extension Default com.netscape.cms.profile.def.KeyUsageExtDefault FINE: PluginRegistry: - nsCertTypeExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nsCertTypeExtDefaultImpl Netscape Certificate Type Extension Default Netscape Certificate Type Extension Default com.netscape.cms.profile.def.NSCertTypeExtDefault FINE: PluginRegistry: - extendedKeyUsageExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy extendedKeyUsageExtDefaultImpl Extended Key Usage Extension Default Extended Key Usage Extension Default com.netscape.cms.profile.def.ExtendedKeyUsageExtDefault FINE: PluginRegistry: - ocspNoCheckExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy ocspNoCheckExtDefaultImpl OCSP No Check Extension Default OCSP No Check Extension Default com.netscape.cms.profile.def.OCSPNoCheckExtDefault FINE: PluginRegistry: - issuerAltNameExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy issuerAltNameExtDefaultImpl Issuer Alternative Name Extension Default Issuer Alternative Name Extension Default com.netscape.cms.profile.def.IssuerAltNameExtDefault FINE: PluginRegistry: - subjectAltNameExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectAltNameExtDefaultImpl Subject Alternative Name Extension Default Subject Alternative Name Extension Default com.netscape.cms.profile.def.SubjectAltNameExtDefault FINE: PluginRegistry: - userSubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userSubjectNameDefaultImpl User Supplied Subject Name Default User Supplied Subject Name Default com.netscape.cms.profile.def.UserSubjectNameDefault FINE: PluginRegistry: - cmcUserSignedSubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy cmcUserSignedSubjectNameDefaultImpl CMC User Signed Subject Name Default CMC User Signed Subject Name Default com.netscape.cms.profile.def.CMCUserSignedSubjectNameDefault FINE: PluginRegistry: - signingAlgDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy signingAlgDefaultImpl Signing Algorithm Default Signing Algorithm Default com.netscape.cms.profile.def.SigningAlgDefault FINE: PluginRegistry: - userKeyDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userKeyDefaultImpl User Supplied Key Default User Supplied Key Default com.netscape.cms.profile.def.UserKeyDefault FINE: PluginRegistry: - userValidityDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userValidityDefaultImpl User Supplied Validity Default User Supplied Validity Default com.netscape.cms.profile.def.UserValidityDefault FINE: PluginRegistry: - userExtensionDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userExtensionDefaultImpl User Supplied Extension Default User Supplied Extension Default com.netscape.cms.profile.def.UserExtensionDefault FINE: PluginRegistry: - userSigningAlgDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userSigningAlgDefaultImpl User Supplied Signing Alg Default User Supplied Signing Alg Default com.netscape.cms.profile.def.UserSigningAlgDefault FINE: PluginRegistry: - authTokenSubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy authTokenSubjectNameDefaultImpl Token Supplied Subject Name Default Token Supplied Subject Name Default com.netscape.cms.profile.def.AuthTokenSubjectNameDefault FINE: PluginRegistry: - subjectInfoAccessExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectInfoAccessExtDefaultImpl Subject Info Access Extension Default Subject Info Access Extension Default com.netscape.cms.profile.def.SubjectInfoAccessExtDefault FINE: PluginRegistry: - authInfoAccessExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy authInfoAccessExtDefaultImpl Authority Info Access Extension Default Authority Info Access Extension Default com.netscape.cms.profile.def.AuthInfoAccessExtDefault FINE: PluginRegistry: - nscCommentExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nscCommentExtDefaultImpl Netscape Comment Extension Default Netscape Comment Extension Default com.netscape.cms.profile.def.NSCCommentExtDefault FINE: PluginRegistry: - freshestCRLExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy freshestCRLExtDefaultImpl Freshest CRL Extension Default Freshest CRL Extension Default com.netscape.cms.profile.def.FreshestCRLExtDefault FINE: PluginRegistry: - crlDistributionPointsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy crlDistributionPointsExtDefaultImpl CRL Distribution Points Extension Default CRL Distribution Points Extension Default com.netscape.cms.profile.def.CRLDistributionPointsExtDefault FINE: PluginRegistry: - policyConstraintsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy policyConstraintsExtDefaultImpl Policy Constraints Extension Default Policy Constraints Extension Default com.netscape.cms.profile.def.PolicyConstraintsExtDefault FINE: PluginRegistry: - policyMappingsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy policyMappingsExtDefaultImpl Policy Mappings Extension Default Policy Mappings Extension Default com.netscape.cms.profile.def.PolicyMappingsExtDefault FINE: PluginRegistry: - nameConstraintsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nameConstraintsExtDefaultImpl Name Constraints Extension Default Name Constraints Extension Default com.netscape.cms.profile.def.NameConstraintsExtDefault FINE: PluginRegistry: - certificateVersionDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy certificateVersionDefaultImpl Certificate Version Default Certificate Version Default com.netscape.cms.profile.def.CertificateVersionDefault FINE: PluginRegistry: - certificatePoliciesExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy certificatePoliciesExtDefaultImpl Certificate Policies Extension Default Certificate Policies Extension Default com.netscape.cms.profile.def.CertificatePoliciesExtDefault FINE: PluginRegistry: - subjectDirAttributesExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectDirAttributesExtDefaultImpl Subject Directory Attributes Extension Default Subject Directory Attributes Extension Default com.netscape.cms.profile.def.SubjectDirAttributesExtDefault FINE: PluginRegistry: - privateKeyPeriodExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy privateKeyPeriodExtDefaultImpl Private Key Period Ext Default Private Key Period Ext Default com.netscape.cms.profile.def.PrivateKeyUsagePeriodExtDefault FINE: PluginRegistry: - inhibitAnyPolicyExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy inhibitAnyPolicyExtDefaultImpl Inhibit Any-Policy Extension Default Inhibit Any-Policy Extension Default com.netscape.cms.profile.def.InhibitAnyPolicyExtDefault FINE: PluginRegistry: - imageDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy imageDefaultImpl Image Default Image Default com.netscape.cms.profile.def.ImageDefault FINE: PluginRegistry: - nsTokenDeviceKeySubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nsTokenDeviceKeySubjectNameDefaultImpl nsTokenDeviceKeySubjectNameDefault nsTokenDeviceKeySubjectNameDefaultImpl com.netscape.cms.profile.def.nsTokenDeviceKeySubjectNameDefault FINE: PluginRegistry: - nsTokenUserKeySubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nsTokenUserKeySubjectNameDefaultImpl nsTokenUserKeySubjectNameDefault nsTokenUserKeySubjectNameDefaultImpl com.netscape.cms.profile.def.nsTokenUserKeySubjectNameDefault FINE: PluginRegistry: - authzRealmDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy authzRealmDefaultImpl Authz Realm Default Authz Realm Default com.netscape.cms.profile.def.AuthzRealmDefault FINE: PluginRegistry: - commonNameToSANDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy commonNameToSANDefaultImpl Copy Common Name to Subject Alternative Name Copy Common Name to Subject Alternative Name com.netscape.cms.profile.def.CommonNameToSANDefault FINE: PluginRegistry: - SignedCertificateTimestampListExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy SignedCertificateTimestampListExtDefaultImpl Certificate Transparency Timestamp List Extension Default Certificate Transparency Timestamp List Extension Default com.netscape.cms.profile.def.SignedCertificateTimestampListExtDefault FINE: PluginRegistry: - sanToCNDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy sanToCNDefaultImpl SAN to CN Default SAN to CN Default com.netscape.cms.profile.def.SANToCNDefault FINE: PluginRegistry: - serverKeygenUserKeyDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy serverKeygenUserKeyDefaultImpl Server-Side Keygen Default Server-Side Keygen Default com.netscape.cms.profile.def.ServerKeygenUserKeyDefault FINE: PluginRegistry: constraintPolicy: FINE: PluginRegistry: - noConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy noConstraintImpl No Constraint No Constraint com.netscape.cms.profile.constraint.NoConstraint FINE: PluginRegistry: - subjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy subjectNameConstraintImpl Subject Name Constraint Subject Name Constraint com.netscape.cms.profile.constraint.SubjectNameConstraint FINE: PluginRegistry: - uniqueSubjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy uniqueSubjectNameConstraintImpl Unique Subject Name Constraint Unique Subject Name Constraint com.netscape.cms.profile.constraint.UniqueSubjectNameConstraint FINE: PluginRegistry: - userSubjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy userSubjectNameConstraintImpl User Subject Name Constraint User Subject Name Constraint com.netscape.cms.profile.constraint.UserSubjectNameConstraint FINE: PluginRegistry: - cmcSharedTokenSubjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy cmcSharedTokenSubjectNameConstraintImpl CMC Shared Token request User Subject Name Constraint CMC Shared Token request User Subject Name Constraint com.netscape.cms.profile.constraint.CMCSharedTokenSubjectNameConstraint FINE: PluginRegistry: - cmcUserSignedSubjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy cmcUserSignedSubjectNameConstraintImpl CMC User-Signed request User Subject Name Constraint CMC User-Signed request User Subject Name Constraint com.netscape.cms.profile.constraint.CMCUserSignedSubjectNameConstraint FINE: PluginRegistry: - caValidityConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy caValidityConstraintImpl CA Validity Constraint CA Validity Constraint com.netscape.cms.profile.constraint.CAValidityConstraint FINE: PluginRegistry: - validityConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy validityConstraintImpl Validity Constraint Validity Constraint com.netscape.cms.profile.constraint.ValidityConstraint FINE: PluginRegistry: - keyUsageExtConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy keyUsageExtConstraintImpl Key Usage Extension Constraint Key Usage Extension Constraint com.netscape.cms.profile.constraint.KeyUsageExtConstraint FINE: PluginRegistry: - nsCertTypeExtConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy nsCertTypeExtConstraintImpl Netscape Certificate Type Extension Constraint Netscape Certificate Type Extension Constraint com.netscape.cms.profile.constraint.NSCertTypeExtConstraint FINE: PluginRegistry: - extendedKeyUsageExtConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy extendedKeyUsageExtConstraintImpl Extended Key Usage Extension Constraint Extended Key Usage Extension Constraint com.netscape.cms.profile.constraint.ExtendedKeyUsageExtConstraint FINE: PluginRegistry: - keyConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy keyConstraintImpl Key Constraint Key Constraint com.netscape.cms.profile.constraint.KeyConstraint FINE: PluginRegistry: - basicConstraintsExtConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy basicConstraintsExtConstraintImpl Basic Constraints Extension Constraint Basic Constraints Extension Constraint com.netscape.cms.profile.constraint.BasicConstraintsExtConstraint FINE: PluginRegistry: - extensionConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy extensionConstraintImpl Extension Constraint Extension Constraint com.netscape.cms.profile.constraint.ExtensionConstraint FINE: PluginRegistry: - signingAlgConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy signingAlgConstraintImpl Signing Algorithm Constraint Signing Algorithm Constraint com.netscape.cms.profile.constraint.SigningAlgConstraint FINE: PluginRegistry: - uniqueKeyConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy uniqueKeyConstraintImpl Unique Public Key Constraint Unique Public Key Constraint com.netscape.cms.profile.constraint.UniqueKeyConstraint FINE: PluginRegistry: - renewGracePeriodConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy renewGracePeriodConstraintImpl Renewal Grace Period Constraint Renewal Grace Period Constraint com.netscape.cms.profile.constraint.RenewGracePeriodConstraint FINE: PluginRegistry: - authzRealmConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy authzRealmConstraintImpl Authz Realm Constraint Authz Realm Constraint com.netscape.cms.profile.constraint.AuthzRealmConstraint FINE: PluginRegistry: - externalProcessConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy externalProcessConstraintImpl External Process Constraint External Process Constraint com.netscape.cms.profile.constraint.ExternalProcessConstraint FINE: PluginRegistry: - p12ExportPasswordConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy p12ExportPasswordConstraintImpl Generated PKCS12 Constraint Generated PKCS12 Constraint com.netscape.cms.profile.constraint.P12ExportPasswordConstraint FINE: PluginRegistry: profileInput: FINE: PluginRegistry: - cmcCertReqInputImpl FINE: PluginRegistry: Added plugin profileInput cmcCertReqInputImpl CMC Certificate Request Input CMC Certificate Request Input com.netscape.cms.profile.input.CMCCertReqInput FINE: PluginRegistry: - certReqInputImpl FINE: PluginRegistry: Added plugin profileInput certReqInputImpl Certificate Request Input Certificate Request Input com.netscape.cms.profile.input.CertReqInput FINE: PluginRegistry: - keyGenInputImpl FINE: PluginRegistry: Added plugin profileInput keyGenInputImpl Key Generation Input Key Generation Input com.netscape.cms.profile.input.KeyGenInput FINE: PluginRegistry: - encKeyGenInputImpl FINE: PluginRegistry: Added plugin profileInput encKeyGenInputImpl Encryption Key Generation Input Encryption Key Generation Input com.netscape.cms.profile.input.EncryptionKeyGenInput FINE: PluginRegistry: - signKeyGenInputImpl FINE: PluginRegistry: Added plugin profileInput signKeyGenInputImpl Encryption Key Generation Input Encryption Key Generation Input com.netscape.cms.profile.input.SigningKeyGenInput FINE: PluginRegistry: - dualKeyGenInputImpl FINE: PluginRegistry: Added plugin profileInput dualKeyGenInputImpl Dual Key Generation Input Dual Key Generation Input com.netscape.cms.profile.input.DualKeyGenInput FINE: PluginRegistry: - subjectNameInputImpl FINE: PluginRegistry: Added plugin profileInput subjectNameInputImpl Subject Name Input Subject Name Input com.netscape.cms.profile.input.SubjectNameInput FINE: PluginRegistry: - submitterInfoInputImpl FINE: PluginRegistry: Added plugin profileInput submitterInfoInputImpl Submitter Information Input Submitter Information Input com.netscape.cms.profile.input.SubmitterInfoInput FINE: PluginRegistry: - genericInputImpl FINE: PluginRegistry: Added plugin profileInput genericInputImpl Generic Input Generic Input com.netscape.cms.profile.input.GenericInput FINE: PluginRegistry: - fileSigningInputImpl FINE: PluginRegistry: Added plugin profileInput fileSigningInputImpl File Signing Input File Signing Input com.netscape.cms.profile.input.FileSigningInput FINE: PluginRegistry: - imageInputImpl FINE: PluginRegistry: Added plugin profileInput imageInputImpl Image Input Image Input com.netscape.cms.profile.input.ImageInput FINE: PluginRegistry: - subjectDNInputImpl FINE: PluginRegistry: Added plugin profileInput subjectDNInputImpl Subject DN Input Subject DN Input com.netscape.cms.profile.input.SubjectDNInput FINE: PluginRegistry: - nsNKeyCertReqInputImpl FINE: PluginRegistry: Added plugin profileInput nsNKeyCertReqInputImpl nsNKeyCertReqInputImpl nsNKeyCertReqInputImpl com.netscape.cms.profile.input.nsNKeyCertReqInput FINE: PluginRegistry: - nsHKeyCertReqInputImpl FINE: PluginRegistry: Added plugin profileInput nsHKeyCertReqInputImpl nsHKeyCertReqInputImpl nsHKeyCertReqInputImpl com.netscape.cms.profile.input.nsHKeyCertReqInput FINE: PluginRegistry: - serialNumRenewInputImpl FINE: PluginRegistry: Added plugin profileInput serialNumRenewInputImpl Certificate Renewal Request Serial Number Input Certificate Renewal Request Serial Number Input com.netscape.cms.profile.input.SerialNumRenewInput FINE: PluginRegistry: - subjectAltNameExtInputImpl FINE: PluginRegistry: Added plugin profileInput subjectAltNameExtInputImpl SAN Input SAN Input com.netscape.cms.profile.input.SubjectAltNameExtInput FINE: PluginRegistry: - serverKeygenInputImpl FINE: PluginRegistry: Added plugin profileInput serverKeygenInputImpl Server-Side Keygen Input Server-Side Keygen Input com.netscape.cms.profile.input.ServerKeygenInput FINE: PluginRegistry: profileOutput: FINE: PluginRegistry: - certOutputImpl FINE: PluginRegistry: Added plugin profileOutput certOutputImpl Certificate Output Certificate Output com.netscape.cms.profile.output.CertOutput FINE: PluginRegistry: - cmmfOutputImpl FINE: PluginRegistry: Added plugin profileOutput cmmfOutputImpl CMMF Response Output CMMF Response Output com.netscape.cms.profile.output.CMMFOutput FINE: PluginRegistry: - pkcs7OutputImpl FINE: PluginRegistry: Added plugin profileOutput pkcs7OutputImpl PKCS7 Output PKCS7 Output com.netscape.cms.profile.output.PKCS7Output FINE: PluginRegistry: - nsNKeyOutputImpl FINE: PluginRegistry: Added plugin profileOutput nsNKeyOutputImpl nsNKeyOutputImpl nsNKeyOutputImpl com.netscape.cms.profile.output.nsNKeyOutput FINE: PluginRegistry: - pkcs12OutputImpl FINE: PluginRegistry: Added plugin profileOutput pkcs12OutputImpl PKCS12 Output PKCS12 Output com.netscape.cms.profile.output.PKCS12Output FINE: PluginRegistry: profileUpdater: FINE: PluginRegistry: - subsystemGroupUpdaterImpl FINE: PluginRegistry: Added plugin profileUpdater subsystemGroupUpdaterImpl Updater for Subsystem Group Updater for Subsystem Group com.netscape.cms.profile.updater.SubsystemGroupUpdater FINE: RegistrySubsystem: startup FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(CAProfileImportCLI) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 3 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: LdapBoundConnFactory: makeNewConnection(false) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: connections will be cloned from the master FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 3 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 3 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 3 INFO: Importing profiles into LDAP INFO: Importing /usr/share/pki/ca/profiles/ca/acmeServerCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCserverCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCECserverCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCECsubsystemCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCsubsystemCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCauditSigningCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCcaCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCocspCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCkraTransportCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCkraStorageCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caServerKeygen_UserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caServerKeygen_DirUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caUserSMIMEcapCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caDualCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caDirBasedDualCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/AdminCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/ECAdminCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caSignedLogCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTPSCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caRARouterCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caRouterCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caServerCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECServerCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caServerCertWithSCT.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECServerCertWithSCT.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caSubsystemCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECSubsystemCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caOtherCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCACert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCcaCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCrossSignedCACert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caInstallCACert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caRACert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caOCSPCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caStorageCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTransportCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caDirPinUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECDirPinUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caDirUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECDirUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caAgentServerCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECAgentServerCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caAgentFileSigning.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCECUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCcaIssuanceProtectionCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caFullCMCUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECFullCMCUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caFullCMCUserSignedCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECFullCMCUserSignedCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caFullCMCSharedTokenCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECFullCMCSharedTokenCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caSimpleCMCUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECSimpleCMCUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenDeviceKeyEnrollment.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserEncryptionKeyEnrollment.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserSigningKeyEnrollment.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTempTokenDeviceKeyEnrollment.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTempTokenUserEncryptionKeyEnrollment.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTempTokenUserSigningKeyEnrollment.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caAdminCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECAdminCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthServerCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECInternalAuthServerCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthTransportCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthDRMstorageCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthSubsystemCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caECInternalAuthSubsystemCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthOCSPCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthAuditSigningCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/DomainController.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caDualRAuserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caRAagentCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caRAserverCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caUUIDdeviceCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caSSLClientSelfRenewal.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caDirUserRenewal.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caManualRenewal.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenMSLoginEnrollment.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserSigningKeyRenewal.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserEncryptionKeyRenewal.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserAuthKeyRenewal.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caJarSigningCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caIPAserviceCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caAuditSigningCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caEncUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caSigningUserCert.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserDelegateAuthKeyEnrollment.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserDelegateSigningKeyEnrollment.cfg FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: initial values. Total: 3, pool: 3 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: master connection is connected: true FINE: LdapBoundConnFactory: number of connections: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).getConn: final values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: initial values. Total: 3, pool: 2 FINE: LdapBoundConnFactory (CAProfileImportCLI).returnConn: final values. Total: 3, pool: 3 INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: Request ID generator: random INFO: Certificate ID generator: random INFO: Enabling CA subsystem INFO: Deploying ca web application INFO: Creating /var/lib/pki/pki-tomcat/conf/Catalina/localhost/ca.xml WARNING: cert_path missing; not used for validation: /var/lib/pki/pki-tomcat/conf/alias/ca.crt DEBUG: PKIDeployer.setup_system_certs() INFO: Setting up signing cert DEBUG: PKISubsystem.get_subsystem_cert(signing) DEBUG: PKISubsystem.get_cert_info(signing) DEBUG: PKISubsystem.get_nssdb_cert_info(signing) DEBUG: NSSDatabase.get_cert_info(caSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(caSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmp_jurjsjf/password.txt -n caSigningCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: caSigningCert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: caSigningCert cert-pki-ca DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(caSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(caSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpc1y1x0_q/password.txt -n caSigningCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: caSigningCert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: caSigningCert cert-pki-ca INFO: signing cert does not exist in NSS database INFO: Creating new signing key in NSS database INFO: Creating signing key DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -C /tmp/tmpigq_dv0a/password.txt nss-key-create --output-format json --key-type RSA --key-size 3072 --debug DEBUG: stdout: -1 INFO: - key ID: 0x0fb10b0d6343210e540c5065862540e09141046c INFO: Creating signing cert request DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-request --subject CN=Certificate Authority,O=UFREEIPA.TEST --csr /tmp/tmpyt2x9yrp/request.csr --key-id 0x0fb10b0d6343210e540c5065862540e09141046c --hash SHA256 --ext /tmp/tmp251hkbkv/request.conf --debug FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: NSSDatabase: Loading key 0x0fb10b0d6343210e540c5065862540e09141046c FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 3072 INFO: Creating basic constraint extension: INFO: - critical INFO: - CA: true INFO: Creating key usage extension: INFO: - critical INFO: - digitalSignature INFO: - nonRepudiation INFO: - keyCertSign INFO: - cRLSign FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: CN=Certificate Authority,O=UFREEIPA.TEST FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: CN=Certificate Authority,O=UFREEIPA.TEST FINE: CryptoUtil: - attributes: FINE: CryptoUtil: - extensions DEBUG: - request: MIIDrzCCAhcCAQAwODEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAt8JdwCaVf5v1Qu5lkZh/ssCL6G+9GdG7frQLF5aK8jT39vQKyFUpSMfK2YTAUUZ8/vg0tgadwFvdBxa6/+22RncDjSqap9he7P/fTT9sZgM5Z3SmQJyHqUYdm0bya0SgiNq675wnfixOXQfB4J0w2RxedYjCLgwC0KzKdHC13mBxFnBeDxagCAyN3MCCRlcn1CQBm9ENPvFQ/SaeKmrzSW21L/rzW07iHvp4yEiE1adf05mxtuOC7BNpIt4uIZ3srZET5vaSTi2D9VrmMpzY3KGWLm84lw2vK7ZyqIFpYAaImhTOLZm/Gp+ZFGfO0FoolGJgp8tij/WsygdffX/gaMu/raZ50u/Axy9SWRnz6DJR6eiF6N9M5Vie1TxLjLUsYEQWkOaekJSFFYQzk3iwDefnWk+2jePuCFgOvhs9VYHOEYPssRGLQlXij0SgC0G7RiR3tpTqNMbWiZpR0kbr/86YnIMznXZXAQ2TecdRlcZZS7VBNJVljBR1RBBQv1ddAgMBAAGgMjAwBgkqhkiG9w0BCQ4xIzAhMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgHGMA0GCSqGSIb3DQEBCwUAA4IBgQB+eb6oZ9+tLJdCVwk0LQY/iQ8xYDk3/qdIDd9XPlEzvGhLZHSgIf/u/xOaxeyNEz2mpyP+KqlN+YbG1gnc/lw1CTRXuxnyG2JoPvQdQ0j59zM4byswgyB5Q6G4p6AhNmiMqhioKcH1NZO1w4kv5mcj5qH92WeZiWVKEciOKStXRItNVq38IQZ4O0sw/Jmym6dIhh8mc96psj4ErlQyC7YHGo12IEkP3LC1GzSthSP0C9cTp9X0xJGNXHsNVlZNpVSvCpj9Mt0D/8eIjFCgcfRe99KX2jPUULUJl+6U8rfvLnY5FhE1sgtChFfYzLR0z86B4DItVUGKFVVIqQcLIbirhhDc4tbDHniYOUFS1q1hoToq0urJGTdgEBjYAuWD5nNhwdjOBhafW2/Wopa+O3EslG+Im1+Pcqilf2AWRedoJaDhLrPORzDkqG2jTupOO4H1UeSn2UMRNlSlAgm5gy6jLpe0foqIbBUrWPyQwfzxhHF9gt6yXWUwWjNpLpF0nOA= INFO: Storing signing cert request INFO: Reusing /var/lib/pki/pki-tomcat/conf/certs INFO: Importing signing cert request into CA database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --type pkcs10 --profile caCert.profile --output-format json INFO: - request ID: 0x18cf22c3e0297e36bec8445bbe45536a INFO: Creating signing cert DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-create --debug --request 0x18cf22c3e0297e36bec8445bbe45536a --profile caCert.profile --type selfsign --key-id 0x0fb10b0d6343210e540c5065862540e09141046c --key-token internal --key-algorithm SHA256withRSA --signing-algorithm SHA256withRSA --format DER INFO: - serial: 0x44f96595603afbb5c22cb9a8012cb1d5 INFO: - subject: CN=Certificate Authority,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: Importing signing cert into NSS database INFO: - nickname: caSigningCert cert-pki-ca DEBUG: NSSDatabase.add_cert(caSigningCert cert-pki-ca) DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-import --format PEM --debug caSigningCert cert-pki-ca FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: Importing cert caSigningCert cert-pki-ca into internal token INFO: Importing signing cert into CA database DEBUG: - cert: MIIEXTCCAsWgAwIBAgIQRPlllWA6+7XCLLmoASyx1TANBgkqhkiG9w0BAQsFADA4MRYwFAYDVQQKDA1VRlJFRUlQQS5URVNUMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMjUwNTA3MTgwMzI5WhcNNDUwNTA3MTgwMzI5WjA4MRYwFAYDVQQKDA1VRlJFRUlQQS5URVNUMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQC3wl3AJpV/m/VC7mWRmH+ywIvob70Z0bt+tAsXloryNPf29ArIVSlIx8rZhMBRRnz++DS2Bp3AW90HFrr/7bZGdwONKpqn2F7s/99NP2xmAzlndKZAnIepRh2bRvJrRKCI2rrvnCd+LE5dB8HgnTDZHF51iMIuDALQrMp0cLXeYHEWcF4PFqAIDI3cwIJGVyfUJAGb0Q0+8VD9Jp4qavNJbbUv+vNbTuIe+njISITVp1/TmbG244LsE2ki3i4hneytkRPm9pJOLYP1WuYynNjcoZYubziXDa8rtnKogWlgBoiaFM4tmb8an5kUZ87QWiiUYmCny2KP9azKB199f+Boy7+tpnnS78DHL1JZGfPoMlHp6IXo30zlWJ7VPEuMtSxgRBaQ5p6QlIUVhDOTeLAN5+daT7aN4+4IWA6+Gz1Vgc4Rg+yxEYtCVeKPRKALQbtGJHe2lOo0xtaJmlHSRuv/zpicgzOddlcBDZN5x1GVxllLtUE0lWWMFHVEEFC/V10CAwEAAaNjMGEwHQYDVR0OBBYEFAb4otKUM95HEMV4ddBDTIlHqY1sMB8GA1UdIwQYMBaAFAb4otKUM95HEMV4ddBDTIlHqY1sMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgHGMA0GCSqGSIb3DQEBCwUAA4IBgQC3PCA8UkLxH5FegYS2/eZWiXTw0Mb01szLmcPxfL2BD8ZphdroqJ3PXcp5O4Xk2CXEKkHu7+iu2hzQNzdvBrYwVCgWgC8t34qa0QAs01NJ1797G7A0UVFy1Ahagd39zDeTEMM5SI6mKLkX4S8X8O1k0DUUab2JOEYZS/nqaUnFn3bjzd0In8N7BhxLkw4xNTsNus5t49/rwiJJfTxdO7w/FBD7FbXMWSq+SX2RK+XNjiq8DiAhaOIGjdgv/9/ma4nMOyOmExIzAfl0B3255bQC2H2UUFRMypYEXfUKZHs4aOJpC0ddz5DGbaRPMqrwhVYRBsKD+CGrzwVL6BNa4xaHQoGd9PUTUWXZvm9Tm78jTsqGIiqF6Gy2E0ZJWnqZD3PyidZ3lhAtaawGZIhJGFa5yMlA7zRIYYgmby0WeQFUhYyEaUm5A1teFNAGpLwHlgjXuw7FtV4OK6WU8iF38KNzPFK2HRfCsYreaQDlECmWedeoS8lqbCBz8pF9xrvNwZE= DEBUG: Command: /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmpputrfvig/cert.crt --format PEM --request 0x18cf22c3e0297e36bec8445bbe45536a --profile caCert.profile INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/caCert.profile FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: SecureRandomFactory: Creating secure random: FINE: SecureRandomFactory: - algorithm: pkcs11prng FINE: SecureRandomFactory: - provider: Mozilla-JSS FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: registered: false INFO: DBSubsystem: Configuring excluded LDAP attributes FINE: DBSubsystem: excludedLdapAttrs.enabled: false FINE: CertificateRepository: number radix 16 FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: random FINE: CertificateRepository: - cert ID length: 128 INFO: Creating cert record 0x44f96595603afbb5c22cb9a8012cb1d5: INFO: - subject: CN=Certificate Authority,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: - request ID: 0x18cf22c3e0297e36bec8445bbe45536a INFO: - profile ID mapping: caCACert FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 FINE: CertificateRepository: Adding certificate record cn=91682445989297502188288508781115781589,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=Certificate Authority,O=UFREEIPA.TEST FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=91682445989297502188288508781115781589,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: DateMapper: - value: Wed May 07 18:03:32 UTC 2025 FINE: DateMapper: - database value: 20250507180332Z FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:03:32 UTC 2025 FINE: DateMapper: - database value: 20250507180332Z FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 INFO: Updating request record 0x18cf22c3e0297e36bec8445bbe45536a FINE: CertificateRepository: number radix 10 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: random FINE: RequestRepository: - request ID length: 128 FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Retrieving cn=32976982469347708893771256903990858602,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: DateMapper: Mapping dateOfCreate to requestCreateTime FINE: DateMapper: - database value: 20250507180327Z FINE: DateMapper: - value: Wed May 07 18:03:27 UTC 2025 FINE: DateMapper: Mapping dateOfModify to requestModifyTime FINE: DateMapper: - database value: 20250507180329Z FINE: DateMapper: - value: Wed May 07 18:03:29 UTC 2025 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: CertRequestRepository: Updating cert for request 0x18cf22c3e0297e36bec8445bbe45536a FINE: CertRequestRepository: - cert serial number: 0x44f96595603afbb5c22cb9a8012cb1d5 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Modifying cn=32976982469347708893771256903990858602,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:03:33 UTC 2025 FINE: DateMapper: - database value: 20250507180333Z FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(DBSubsystem) INFO: Setting up ocsp_signing cert DEBUG: PKISubsystem.get_subsystem_cert(ocsp_signing) DEBUG: PKISubsystem.get_cert_info(ocsp_signing) DEBUG: PKISubsystem.get_nssdb_cert_info(ocsp_signing) DEBUG: NSSDatabase.get_cert_info(ocspSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(ocspSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpsvnswlir/password.txt -n ocspSigningCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: ocspSigningCert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: ocspSigningCert cert-pki-ca DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(ocspSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(ocspSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmptiz788sb/password.txt -n ocspSigningCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: ocspSigningCert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: ocspSigningCert cert-pki-ca INFO: ocsp_signing cert does not exist in NSS database INFO: Creating new ocsp_signing key in NSS database INFO: Creating ocsp_signing key DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -C /tmp/tmpfhfgacd9/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --debug DEBUG: stdout: -1 INFO: - key ID: 0x2d298c5231069d2bf128f1a67de56c9d85252649 INFO: Creating ocsp_signing cert request DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-request --subject cn=OCSP Subsystem,O=UFREEIPA.TEST --csr /tmp/tmpi_bjcl35/request.csr --key-id 0x2d298c5231069d2bf128f1a67de56c9d85252649 --hash SHA256 --debug FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: NSSDatabase: Loading key 0x2d298c5231069d2bf128f1a67de56c9d85252649 FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=OCSP Subsystem,O=UFREEIPA.TEST FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=OCSP Subsystem,O=UFREEIPA.TEST FINE: CryptoUtil: - attributes: DEBUG: - request: MIICdjCCAV4CAQAwMTEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEXMBUGA1UEAwwOT0NTUCBTdWJzeXN0ZW0wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDIovKBjRgDAEar2stUW1DQ19X8tg87C/2zkR4FH53GsmGc9ue7oaBj3ur3PX9XNv4DMvWtS9AYrA1T0danSLeKvUbreRWPu39jCxl1WFEvU4CnZ4dIIZuUOGeJHBJKKrJ7X9x/mGBpIuvLOCF1aPkGDMHbTeabXAeMFM+rGOzqoIHMwny08VoFDnfEhFoPZAZgUXkIjFxoGBL6Px9yXaG73Lb8TSnDUCZmmLaaLTkIrpj4SLAArxc73EVu2YqIqeg9g82yvvvwRU7+aRBvNN5rHY8+dZHGLO8LGrPgKaMmusmvJNUHIXgU3oKmguaVIr9wBnCAUkgCoLaZcO6/9YGvAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAL20QNcRin4g8NxSyCdLF8iMPnajzwP3d7c4qeLW2HQi8RjwFnmSkTYMujBf5x7ihA8aXYsoxerMq3HGWePKAYLOF/Xh+5iCsUDxD8dZk59IsOnLc6fzDM3hcvqT9GHojPDsguo5WfNPzBgql2Zu6/MEotlkVAMGW6Bnu06FVFodlxeYkfEL5Xb3yBKyqByQmCQIZ0kqrKPxbkMVN/R2LmrgbxGAoghocsaW0i/mT0zPX9LA69F8ur4kbbL7ks0HkBeOOn9fVOpSgz04tFwPjS1GHNKVAGKj7wUrW5zNWzyYwOw4uNa1P5+KAXlWYy33/gqkjoIE8ZhScbDOM8GW8nA== INFO: Storing ocsp_signing cert request INFO: Reusing /var/lib/pki/pki-tomcat/conf/certs INFO: Importing ocsp_signing cert request into CA database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --type pkcs10 --profile caOCSPCert.profile --adjust-validity --output-format json INFO: - request ID: 0x9530b809383673823153ab2136105c6b INFO: Creating ocsp_signing cert DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-create --debug --request 0x9530b809383673823153ab2136105c6b --profile caOCSPCert.profile --type local --key-id 0x2d298c5231069d2bf128f1a67de56c9d85252649 --key-token internal --key-algorithm SHA256withRSA --signing-algorithm SHA256withRSA --format DER INFO: - serial: 0x467a15c95ad02926857e3647b473a4b6 INFO: - subject: CN=OCSP Subsystem,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: Importing ocsp_signing cert into NSS database INFO: - nickname: ocspSigningCert cert-pki-ca DEBUG: NSSDatabase.add_cert(ocspSigningCert cert-pki-ca) DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-import --format PEM --debug ocspSigningCert cert-pki-ca FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: Importing cert ocspSigningCert cert-pki-ca into internal token INFO: Importing ocsp_signing cert into CA database DEBUG: - cert: MIID/zCCAmegAwIBAgIQRnoVyVrQKSaFfjZHtHOktjANBgkqhkiG9w0BAQsFADA4MRYwFAYDVQQKDA1VRlJFRUlQQS5URVNUMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMjUwNTA3MTgwMzM4WhcNMjcwNDI3MTgwMzM4WjAxMRYwFAYDVQQKDA1VRlJFRUlQQS5URVNUMRcwFQYDVQQDDA5PQ1NQIFN1YnN5c3RlbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMii8oGNGAMARqvay1RbUNDX1fy2DzsL/bORHgUfncayYZz257uhoGPe6vc9f1c2/gMy9a1L0BisDVPR1qdIt4q9Rut5FY+7f2MLGXVYUS9TgKdnh0ghm5Q4Z4kcEkoqsntf3H+YYGki68s4IXVo+QYMwdtN5ptcB4wUz6sY7OqggczCfLTxWgUOd8SEWg9kBmBReQiMXGgYEvo/H3JdobvctvxNKcNQJmaYtpotOQiumPhIsACvFzvcRW7Zioip6D2DzbK++/BFTv5pEG803msdjz51kcYs7wsas+Apoya6ya8k1QcheBTegqaC5pUiv3AGcIBSSAKgtplw7r/1ga8CAwEAAaOBizCBiDAfBgNVHSMEGDAWgBQG+KLSlDPeRxDFeHXQQ0yJR6mNbDA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAGGI2h0dHA6Ly9pcGEtY2EudWZyZWVpcGEudGVzdC9jYS9vY3NwMBMGA1UdJQQMMAoGCCsGAQUFBwMJMA8GCSsGAQUFBzABBQQCBQAwDQYJKoZIhvcNAQELBQADggGBAAs4CFtejQyL68pQNYT11Ff1lkKwrmC/GtPaArclganLTJpKenn4uiltRr2l7iGw4I2srIr/Zz0plFFqxzcZ5OySC/Y4AETKNPcezUcdk21bQEYH+I7Keh2s1UBjlLuoiCRrOwF/d8Y2eqkOaCYQC1oFa7E0La/riqgLOngn+NwLxuKlXhn4ETWtv+5YB+FLszuce3Dxsp5rO74O/RIpE29SNEaG0JHsFZxCeHknTydngaIXvpcQ9phN87qIXicMS6uE4qqWONCZbfQg7jwumCvxMsv76WHumln8mVKHjZgalQKnRL7PJua0/pU417iKrWIxxGqd4VbAFObV+MhiUVKfwQIOslrL0J+5lBn+zhqUBVI5uw5NsDqmRaNNfvqnh1ndlz//NpXYkVQZjVFRVKl5BvcWDPvybKO3YOUGpIS1uCmQ1HPhmK0J1UDagaspipDbu24UzuyU+bg1thLno82KGD1VfAdX3womFFrKfhRzQhNzMiXa4n+nSLzEAsVf6A== DEBUG: Command: /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmpfmju_5go/cert.crt --format PEM --request 0x9530b809383673823153ab2136105c6b --profile caOCSPCert.profile INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/caOCSPCert.profile FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: SecureRandomFactory: Creating secure random: FINE: SecureRandomFactory: - algorithm: pkcs11prng FINE: SecureRandomFactory: - provider: Mozilla-JSS FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: registered: false INFO: DBSubsystem: Configuring excluded LDAP attributes FINE: DBSubsystem: excludedLdapAttrs.enabled: false FINE: CertificateRepository: number radix 16 FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: random FINE: CertificateRepository: - cert ID length: 128 INFO: Creating cert record 0x467a15c95ad02926857e3647b473a4b6: INFO: - subject: CN=OCSP Subsystem,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: - request ID: 0x9530b809383673823153ab2136105c6b INFO: - profile ID mapping: caOCSPCert FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 FINE: CertificateRepository: Adding certificate record cn=93679861805253003908180131012093912246,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=OCSP Subsystem,O=UFREEIPA.TEST FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=93679861805253003908180131012093912246,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: DateMapper: - value: Wed May 07 18:03:41 UTC 2025 FINE: DateMapper: - database value: 20250507180341Z FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:03:41 UTC 2025 FINE: DateMapper: - database value: 20250507180341Z FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 INFO: Updating request record 0x9530b809383673823153ab2136105c6b FINE: CertificateRepository: number radix 10 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: random FINE: RequestRepository: - request ID length: 128 FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Retrieving cn=198307934314979659342604906547224009835,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: DateMapper: Mapping dateOfCreate to requestCreateTime FINE: DateMapper: - database value: 20250507180336Z FINE: DateMapper: - value: Wed May 07 18:03:36 UTC 2025 FINE: DateMapper: Mapping dateOfModify to requestModifyTime FINE: DateMapper: - database value: 20250507180338Z FINE: DateMapper: - value: Wed May 07 18:03:38 UTC 2025 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: CertRequestRepository: Updating cert for request 0x9530b809383673823153ab2136105c6b FINE: CertRequestRepository: - cert serial number: 0x467a15c95ad02926857e3647b473a4b6 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Modifying cn=198307934314979659342604906547224009835,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:03:42 UTC 2025 FINE: DateMapper: - database value: 20250507180342Z FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(DBSubsystem) INFO: Setting up sslserver cert DEBUG: PKISubsystem.get_subsystem_cert(sslserver) DEBUG: PKISubsystem.get_cert_info(sslserver) DEBUG: PKISubsystem.get_nssdb_cert_info(sslserver) DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmptakbyai1/password.txt -n Server-Cert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: Server-Cert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: Server-Cert cert-pki-ca DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpq_fqsct6/password.txt -n Server-Cert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: Server-Cert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: Server-Cert cert-pki-ca INFO: sslserver cert does not exist in NSS database INFO: Creating new sslserver key in NSS database INFO: Creating sslserver key DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -C /tmp/tmp5vk5lszw/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --debug DEBUG: stdout: -1 INFO: - key ID: 0xeb0e8d2695321ab7fb1ba2dd5c3406e25092eda7 INFO: Creating sslserver cert request DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-request --subject cn=master.ufreeipa.test,O=UFREEIPA.TEST --csr /tmp/tmp92f625c8/request.csr --key-id 0xeb0e8d2695321ab7fb1ba2dd5c3406e25092eda7 --hash SHA256 --debug FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: NSSDatabase: Loading key 0xeb0e8d2695321ab7fb1ba2dd5c3406e25092eda7 FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=master.ufreeipa.test,O=UFREEIPA.TEST FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=master.ufreeipa.test,O=UFREEIPA.TEST FINE: CryptoUtil: - attributes: DEBUG: - request: MIICfDCCAWQCAQAwNzEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEdMBsGA1UEAwwUbWFzdGVyLnVmcmVlaXBhLnRlc3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCY63K+VAA0DO6dW3U8FGsdz4J/9fqBi8kBro/hSVYQ6iI8utf+UWBW3JrEUYvrILWjVeXbx0QFScB/NiGkCocO8fvXfMgPeEWovtWCYZiHZdNqwL03wqHWjsUHLcLDikTAaJN93wDhB+tZEXZxQA2iOU3icdJw33jsoNdqjwDkv4ElFnGWPILIx1ZkbGbmIyjo1r4ZHJkXBVdhnQmuja1rCDRl/41CwN8EtEjsgiVDloBANhcQ7i3FGfaBdqLJhrjC05Xtm2rSzPkMaFTQpmk1HtSk3x7stMhiYLG/FaoJjcuNAk44LmrZmVNcDeclOHjoyzrgfU8LwVb5bzCQpMXFAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAHl9mOqRJN/qvbFuIYNuhjVvpQCk9Y9Jlj2NtFTnON1WJein/T0UTmaGdcwAxC1QshA2OxEp+NYg2yhR7O2nz7p4Dsg3h5AUV19M/gEp5IJK5f+ivPKd9OYxmjeiI6967j5PqtihCyk4huWkBiNUQvC16Kj4ji/79LbwK/bjU3BShZHcBY5tzLMYQT2MoG16rm5X0vtHy+KNtlBv4nz2Co4uEXn1i5giiovXloDK+2wijx/qydfmNkOsuJbNUwp2Uu3zpKttOlI1clhCWrNQ2BHEjfgNzIh+GauAZxsgtxkCIL1CgmVoReXETSYJAaWUEcT7R+Jjf3Gt1yImjRWd4Dw== INFO: Storing sslserver cert request INFO: Reusing /var/lib/pki/pki-tomcat/conf/certs INFO: Importing sslserver cert request into CA database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --type pkcs10 --profile serverCert.profile --adjust-validity --output-format json INFO: - request ID: 0x9ae588b235b98c915b2cf21ac21d1f9e INFO: Creating sslserver cert DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-create --debug --request 0x9ae588b235b98c915b2cf21ac21d1f9e --profile serverCert.profile --type local --key-id 0xeb0e8d2695321ab7fb1ba2dd5c3406e25092eda7 --key-token internal --key-algorithm SHA256withRSA --signing-algorithm SHA256withRSA --format DER INFO: - serial: 0x26c0cef3e4f83c7616d6bbb9b77e9647 INFO: - subject: CN=master.ufreeipa.test,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: Importing sslserver cert into NSS database INFO: - nickname: Server-Cert cert-pki-ca DEBUG: NSSDatabase.add_cert(Server-Cert cert-pki-ca) DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-import --format PEM --debug Server-Cert cert-pki-ca FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: Importing cert Server-Cert cert-pki-ca into internal token INFO: Importing sslserver cert into CA database DEBUG: - cert: MIIEJTCCAo2gAwIBAgIQJsDO8+T4PHYW1ru5t36WRzANBgkqhkiG9w0BAQsFADA4MRYwFAYDVQQKDA1VRlJFRUlQQS5URVNUMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMjUwNTA3MTgwMzQ3WhcNMjcwNDI3MTgwMzQ3WjA3MRYwFAYDVQQKDA1VRlJFRUlQQS5URVNUMR0wGwYDVQQDDBRtYXN0ZXIudWZyZWVpcGEudGVzdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJjrcr5UADQM7p1bdTwUax3Pgn/1+oGLyQGuj+FJVhDqIjy61/5RYFbcmsRRi+sgtaNV5dvHRAVJwH82IaQKhw7x+9d8yA94Rai+1YJhmIdl02rAvTfCodaOxQctwsOKRMBok33fAOEH61kRdnFADaI5TeJx0nDfeOyg12qPAOS/gSUWcZY8gsjHVmRsZuYjKOjWvhkcmRcFV2GdCa6NrWsINGX/jULA3wS0SOyCJUOWgEA2FxDuLcUZ9oF2osmGuMLTle2batLM+QxoVNCmaTUe1KTfHuy0yGJgsb8VqgmNy40CTjguatmZU1wN5yU4eOjLOuB9TwvBVvlvMJCkxcUCAwEAAaOBqzCBqDAfBgNVHSMEGDAWgBQG+KLSlDPeRxDFeHXQQ0yJR6mNbDA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAGGI2h0dHA6Ly9pcGEtY2EudWZyZWVpcGEudGVzdC9jYS9vY3NwMA4GA1UdDwEB/wQEAwIEsDATBgNVHSUEDDAKBggrBgEFBQcDATAfBgNVHREEGDAWghRtYXN0ZXIudWZyZWVpcGEudGVzdDANBgkqhkiG9w0BAQsFAAOCAYEAeSvsEjoo7s93VEr4sLcAS5DPk9Z1tdtRcKja/oswKMSaR8A1kCcz/CdWCcH3/cD8Mb5B0VIZuxUdXthcCgMs8tM6+oBvwlebNF/UKDFyX6/xVBew+wFoNCR6yY1Uv3wrC+1whzDtd21sA7boFHBdAbbuLIBUuEmfSQOeF799xPMgMybat7n3fQAoBRZUPF8LXDb1s3fuRbHodSJ1eysgt79Lw+hshoSWcLOyweFFhBAzWuWvxCXD9gdP06gr3RMsBzQ1pWDfAohbA4qoGQMuEsyGXpLK4pcLAC5LIGwP+QShuwiHwF3YP2ITqx7PJd+QHhv4YFoDhfC9i8X7L9xxt7qufH37NcErIXIDAe0mAB3xkA/6oM2XmfCpVdN3YfSzfptMDvO8RHkleEjBjRbr5JRPAG5yuUtNPdsWIK3Ii1LyCsGajxJ2qoxGSrBy6JXgC+SoQSJ3+E9MTFvUbmt3d1D5lKS3ynoQx3i/lEEvbXv2/NczZu0YPdiW2nO3ZWCC DEBUG: Command: /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmp3crcnk5m/cert.crt --format PEM --request 0x9ae588b235b98c915b2cf21ac21d1f9e --profile serverCert.profile INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/serverCert.profile FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: SecureRandomFactory: Creating secure random: FINE: SecureRandomFactory: - algorithm: pkcs11prng FINE: SecureRandomFactory: - provider: Mozilla-JSS FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: registered: false INFO: DBSubsystem: Configuring excluded LDAP attributes FINE: DBSubsystem: excludedLdapAttrs.enabled: false FINE: CertificateRepository: number radix 16 FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: random FINE: CertificateRepository: - cert ID length: 128 INFO: Creating cert record 0x26c0cef3e4f83c7616d6bbb9b77e9647: INFO: - subject: CN=master.ufreeipa.test,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: - request ID: 0x9ae588b235b98c915b2cf21ac21d1f9e INFO: - profile ID mapping: caServerCert FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 FINE: CertificateRepository: Adding certificate record cn=51511782336350014648245477651997693511,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=master.ufreeipa.test,O=UFREEIPA.TEST FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=51511782336350014648245477651997693511,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: DateMapper: - value: Wed May 07 18:03:50 UTC 2025 FINE: DateMapper: - database value: 20250507180350Z FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:03:50 UTC 2025 FINE: DateMapper: - database value: 20250507180350Z FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 INFO: Updating request record 0x9ae588b235b98c915b2cf21ac21d1f9e FINE: CertificateRepository: number radix 10 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: random FINE: RequestRepository: - request ID length: 128 FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Retrieving cn=205892919858427564730164899050677936030,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: DateMapper: Mapping dateOfCreate to requestCreateTime FINE: DateMapper: - database value: 20250507180345Z FINE: DateMapper: - value: Wed May 07 18:03:45 UTC 2025 FINE: DateMapper: Mapping dateOfModify to requestModifyTime FINE: DateMapper: - database value: 20250507180347Z FINE: DateMapper: - value: Wed May 07 18:03:47 UTC 2025 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: CertRequestRepository: Updating cert for request 0x9ae588b235b98c915b2cf21ac21d1f9e FINE: CertRequestRepository: - cert serial number: 0x26c0cef3e4f83c7616d6bbb9b77e9647 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Modifying cn=205892919858427564730164899050677936030,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:03:51 UTC 2025 FINE: DateMapper: - database value: 20250507180351Z FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(DBSubsystem) INFO: Setting up subsystem cert DEBUG: PKISubsystem.get_subsystem_cert(subsystem) DEBUG: PKISubsystem.get_cert_info(subsystem) DEBUG: PKISubsystem.get_nssdb_cert_info(subsystem) DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpn3xucm0v/password.txt -n subsystemCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: subsystemCert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: subsystemCert cert-pki-ca DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmp2b5yw7jo/password.txt -n subsystemCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: subsystemCert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: subsystemCert cert-pki-ca INFO: subsystem cert does not exist in NSS database INFO: Creating new subsystem key in NSS database INFO: Creating subsystem key DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -C /tmp/tmp5hhb_1h2/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --debug DEBUG: stdout: -1 INFO: - key ID: 0xa355b9c5673a67ff0542e696c69fc1b8dbb5ad65 INFO: Creating subsystem cert request DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-request --subject cn=CA Subsystem,O=UFREEIPA.TEST --csr /tmp/tmpeumur5w9/request.csr --key-id 0xa355b9c5673a67ff0542e696c69fc1b8dbb5ad65 --hash SHA256 --debug FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: NSSDatabase: Loading key 0xa355b9c5673a67ff0542e696c69fc1b8dbb5ad65 FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=CA Subsystem,O=UFREEIPA.TEST FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=CA Subsystem,O=UFREEIPA.TEST FINE: CryptoUtil: - attributes: DEBUG: - request: MIICdDCCAVwCAQAwLzEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEVMBMGA1UEAwwMQ0EgU3Vic3lzdGVtMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuxwoUwizA3O25xjbYWVysNbDtbyMShn9kicFcPaWCZioUwfbhqroBTGnR+jJA7A8xMyW5h4uukd2vxXUBVvsl7e5JOjrdV5aoK23ih2xPBuY71APsuQq8VEjeC9S98C25YdnLkqv6oOi8QlBlTaauO6P9syjiefnKpVI+1vbLH5sd5OvKo/WwlORXO9yzWZhj7HThasBP3hqNCpCgwScvpM3tgbdi4jWXOllTRrYDKZCAo3JfWGgylowKQvj0iHCuhGzFEokZ1kIedp6lGmTQqjmXo4m0ScwG4p1d89+hPYyIbzKKXHvDvoxgKO/gyJnEwogAYxBc54FM3eNqel2WQIDAQABoAAwDQYJKoZIhvcNAQELBQADggEBAGuikRcZj2/D9C0mEpQMC67TcIh8bRD6dDKp3t/b96dxNJg+6oIV9/o0GxV4DQaM3MJMG4tqZxeIAW7f5bK1vVxreT8ZWiAea1jASBmGg1yNEMwyEv3NHDtxDF7UyblUqZqWje7ACnp7LEI7/8O/ttvlflv2REkQYIZ7ovSDDOR/rQoGNRk7epyTBc4o2T8U5iwPlv2lqqXRrgTm0lntjZdJXX5UhvtR3ciKInKje0twgsg6s8YepKAb85IeO/mKJjX5U3AM+rQfW6uilrcp3GEHiBOOLwDuE48OofvCITtSc1bA9UOjuG3Zeaf/4sHQwm6AONMRx+MuqMYKwLBMkM8= INFO: Storing subsystem cert request INFO: Reusing /var/lib/pki/pki-tomcat/conf/certs INFO: Importing subsystem cert request into CA database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --type pkcs10 --profile subsystemCert.profile --adjust-validity --output-format json INFO: - request ID: 0xbdb4d8003281f0b231b7f8afe5ded866 INFO: Creating subsystem cert DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-create --debug --request 0xbdb4d8003281f0b231b7f8afe5ded866 --profile subsystemCert.profile --type local --key-id 0xa355b9c5673a67ff0542e696c69fc1b8dbb5ad65 --key-token internal --key-algorithm SHA256withRSA --signing-algorithm SHA256withRSA --format DER INFO: - serial: 0xcba7683b2ccaa7c7f0f03addc7451a66 INFO: - subject: CN=CA Subsystem,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: Importing subsystem cert into NSS database INFO: - nickname: subsystemCert cert-pki-ca DEBUG: NSSDatabase.add_cert(subsystemCert cert-pki-ca) DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-import --format PEM --debug subsystemCert cert-pki-ca FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: Importing cert subsystemCert cert-pki-ca into internal token INFO: Importing subsystem cert into CA database DEBUG: - cert: MIID/TCCAmWgAwIBAgIRAMunaDssyqfH8PA63cdFGmYwDQYJKoZIhvcNAQELBQAwODEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTI1MDUwNzE4MDM1N1oXDTI3MDQyNzE4MDM1N1owLzEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEVMBMGA1UEAwwMQ0EgU3Vic3lzdGVtMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuxwoUwizA3O25xjbYWVysNbDtbyMShn9kicFcPaWCZioUwfbhqroBTGnR+jJA7A8xMyW5h4uukd2vxXUBVvsl7e5JOjrdV5aoK23ih2xPBuY71APsuQq8VEjeC9S98C25YdnLkqv6oOi8QlBlTaauO6P9syjiefnKpVI+1vbLH5sd5OvKo/WwlORXO9yzWZhj7HThasBP3hqNCpCgwScvpM3tgbdi4jWXOllTRrYDKZCAo3JfWGgylowKQvj0iHCuhGzFEokZ1kIedp6lGmTQqjmXo4m0ScwG4p1d89+hPYyIbzKKXHvDvoxgKO/gyJnEwogAYxBc54FM3eNqel2WQIDAQABo4GKMIGHMB8GA1UdIwQYMBaAFAb4otKUM95HEMV4ddBDTIlHqY1sMD8GCCsGAQUFBwEBBDMwMTAvBggrBgEFBQcwAYYjaHR0cDovL2lwYS1jYS51ZnJlZWlwYS50ZXN0L2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMBMGA1UdJQQMMAoGCCsGAQUFBwMCMA0GCSqGSIb3DQEBCwUAA4IBgQAyEKZCatdUUpfHs6OcmuJ6zGd+htMktOzHXIrCsmH9hzmh62lAD9sOQiMIapyhlvVOAYsSY+NeUgV2Rshaoq2GEPWExe6v3HQTPjALxD4pLSP8xiRouW0DHmb3R9uUDI14OMV8zckOfiBZgP21Obr2sJgocibbihCxERXlPMJTqiw4DMCLbVj9mQiLJi7dPR36svZ5ZORUtYLhOk/oFHgvgkqwzW9Gz50bygDTHYU9A8IiG/duFTZJSD+GPyIQZisyP5MRmmvfMVLdOFQWNazClIANxiktMO9DRg/77s+AbmW6rO6aO5fzcKbYJskcNL7qQHJs6OPrEAVsnlxtg26ruehhAmewOcXVain23yufQRMgB7vvIFmmws2H8bR48nLqyuvMPgrmuR4srjhqK2hiUBD8LoX2ZiSq+3FCrYDYQx23yokL/Ef6tPrJAd4XP4TiMhHBqj2vvPSBSNoiyuBcnyKlPZm+1aZhquOfBuVFy86zFBFkAht5Gxv9Tz33GOM= DEBUG: Command: /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmpha9ju68d/cert.crt --format PEM --request 0xbdb4d8003281f0b231b7f8afe5ded866 --profile subsystemCert.profile INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/subsystemCert.profile FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: SecureRandomFactory: Creating secure random: FINE: SecureRandomFactory: - algorithm: pkcs11prng FINE: SecureRandomFactory: - provider: Mozilla-JSS FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: registered: false INFO: DBSubsystem: Configuring excluded LDAP attributes FINE: DBSubsystem: excludedLdapAttrs.enabled: false FINE: CertificateRepository: number radix 16 FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: random FINE: CertificateRepository: - cert ID length: 128 INFO: Creating cert record 0xcba7683b2ccaa7c7f0f03addc7451a66: INFO: - subject: CN=CA Subsystem,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: - request ID: 0xbdb4d8003281f0b231b7f8afe5ded866 INFO: - profile ID mapping: caSubsystemCert FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 FINE: CertificateRepository: Adding certificate record cn=270702510778635942299924923960967633510,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=CA Subsystem,O=UFREEIPA.TEST FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=270702510778635942299924923960967633510,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: DateMapper: - value: Wed May 07 18:04:00 UTC 2025 FINE: DateMapper: - database value: 20250507180400Z FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:04:00 UTC 2025 FINE: DateMapper: - database value: 20250507180400Z FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 INFO: Updating request record 0xbdb4d8003281f0b231b7f8afe5ded866 FINE: CertificateRepository: number radix 10 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: random FINE: RequestRepository: - request ID length: 128 FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Retrieving cn=252163085653991096289623076236406216806,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: DateMapper: Mapping dateOfCreate to requestCreateTime FINE: DateMapper: - database value: 20250507180355Z FINE: DateMapper: - value: Wed May 07 18:03:55 UTC 2025 FINE: DateMapper: Mapping dateOfModify to requestModifyTime FINE: DateMapper: - database value: 20250507180357Z FINE: DateMapper: - value: Wed May 07 18:03:57 UTC 2025 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: CertRequestRepository: Updating cert for request 0xbdb4d8003281f0b231b7f8afe5ded866 FINE: CertRequestRepository: - cert serial number: 0xcba7683b2ccaa7c7f0f03addc7451a66 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Modifying cn=252163085653991096289623076236406216806,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:04:01 UTC 2025 FINE: DateMapper: - database value: 20250507180401Z FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(DBSubsystem) INFO: Setting up audit_signing cert DEBUG: PKISubsystem.get_subsystem_cert(audit_signing) DEBUG: PKISubsystem.get_cert_info(audit_signing) DEBUG: PKISubsystem.get_nssdb_cert_info(audit_signing) DEBUG: NSSDatabase.get_cert_info(auditSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(auditSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpbomb2xji/password.txt -n auditSigningCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: auditSigningCert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: auditSigningCert cert-pki-ca DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(auditSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(auditSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpvscyz_6u/password.txt -n auditSigningCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: auditSigningCert cert-pki-ca : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: auditSigningCert cert-pki-ca INFO: audit_signing cert does not exist in NSS database INFO: Creating new audit_signing key in NSS database INFO: Creating audit_signing key DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -C /tmp/tmpcgl7a6ox/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --debug DEBUG: stdout: -1 INFO: - key ID: 0x1c3edb13289e60ae83651d8caad553cbc803e62e INFO: Creating audit_signing cert request DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-request --subject cn=CA Audit,O=UFREEIPA.TEST --csr /tmp/tmpbmivac59/request.csr --key-id 0x1c3edb13289e60ae83651d8caad553cbc803e62e --hash SHA256 --debug FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: NSSDatabase: Loading key 0x1c3edb13289e60ae83651d8caad553cbc803e62e FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=CA Audit,O=UFREEIPA.TEST FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=CA Audit,O=UFREEIPA.TEST FINE: CryptoUtil: - attributes: DEBUG: - request: MIICcDCCAVgCAQAwKzEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDERMA8GA1UEAwwIQ0EgQXVkaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQD5RiDF0mRTt+5o4WWRdr5yAb8YXoPkTnuxuqgZHENmzNqghry8lqnfKVemvm2vrP21umXUeghiMvxIYjPdRYHDY9/QGyfOLUY/ZHwYMlPL9JoRH3Tvp2lWo0rOXgoXkGCKOwj5jdeG4jok5X/iK7ATF14GqgpQ6KJhevBO2xwb1YsEVJ3qPaHooB/VD90N+DFIn3NkF8MplX76U7PPw9KYKvsZCNZWWyPOxaebI2/kpQtIIrUu4dLwX5p+knEnTGzaU5MibqqkIF3DuEvVCPSvgkHShnXatnotDkHyg4ZemaoTSvptjTxWZXOsekNZLvb2at/Yw9H/kEe2wIp0C23TAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEA5aLewyjtx7DTBBRFo4zPBGVy2yXRuS641iNt2im+aTVLQFt0N0dxNSwZY6O8/rdPu3TyQhtlsSy8N+NRKy2PIEPRk4GnFbnfKoJN3XJEd0JC35o1JiScUxiY7XeArnTEX/1acKCKqi8iKkvNLr7jz8hoahKBOMVkCQm3fGuFmu9xeC7g4T5DF5+9cnLvIX5cqqqlGqnNEGhRmttBj/xLaVKhhCkNEKP+uYwyLewiqQOoebjIyl9poy+blAeH3HNhYdPd7CGPQ2PHKQD+1r9HaT+XvcX30h17KN0RDVxoGyFiHd0zo8mA61uUZozzhcenZfk9FciT5kVASZGWp8Ln2g== INFO: Storing audit_signing cert request INFO: Reusing /var/lib/pki/pki-tomcat/conf/certs INFO: Importing audit_signing cert request into CA database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --type pkcs10 --profile caAuditSigningCert.profile --adjust-validity --output-format json INFO: - request ID: 0x3de4ca8a80ded6b63d14a2504a1333a0 INFO: Creating audit_signing cert DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-create --debug --request 0x3de4ca8a80ded6b63d14a2504a1333a0 --profile caAuditSigningCert.profile --type local --key-id 0x1c3edb13289e60ae83651d8caad553cbc803e62e --key-token internal --key-algorithm SHA256withRSA --signing-algorithm SHA256withRSA --format DER INFO: - serial: 0xbc8022f916c5254e07ca3af453fc74d5 INFO: - subject: CN=CA Audit,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: Importing audit_signing cert into NSS database INFO: - nickname: auditSigningCert cert-pki-ca DEBUG: NSSDatabase.add_cert(auditSigningCert cert-pki-ca) DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf nss-cert-import --format PEM --debug auditSigningCert cert-pki-ca FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: Importing cert auditSigningCert cert-pki-ca into internal token INFO: Importing audit_signing cert into CA database DEBUG: - cert: MIID4jCCAkqgAwIBAgIRALyAIvkWxSVOB8o69FP8dNUwDQYJKoZIhvcNAQELBQAwODEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTI1MDUwNzE4MDQwNloXDTI3MDQyNzE4MDQwNlowKzEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDERMA8GA1UEAwwIQ0EgQXVkaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQD5RiDF0mRTt+5o4WWRdr5yAb8YXoPkTnuxuqgZHENmzNqghry8lqnfKVemvm2vrP21umXUeghiMvxIYjPdRYHDY9/QGyfOLUY/ZHwYMlPL9JoRH3Tvp2lWo0rOXgoXkGCKOwj5jdeG4jok5X/iK7ATF14GqgpQ6KJhevBO2xwb1YsEVJ3qPaHooB/VD90N+DFIn3NkF8MplX76U7PPw9KYKvsZCNZWWyPOxaebI2/kpQtIIrUu4dLwX5p+knEnTGzaU5MibqqkIF3DuEvVCPSvgkHShnXatnotDkHyg4ZemaoTSvptjTxWZXOsekNZLvb2at/Yw9H/kEe2wIp0C23TAgMBAAGjdDByMB8GA1UdIwQYMBaAFAb4otKUM95HEMV4ddBDTIlHqY1sMA4GA1UdDwEB/wQEAwIGwDA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAGGI2h0dHA6Ly9pcGEtY2EudWZyZWVpcGEudGVzdC9jYS9vY3NwMA0GCSqGSIb3DQEBCwUAA4IBgQCpFfxtvHqkUg+Mem63hFA4DZXjcVAg1EISDkkS6rEr++HrKEYLF4S9mAEdN2xw6d6/7etwo19wbGTU2NxX3zb9R/Pg7OWj1d0K38nTYAt6rkz+LCJOz4vCSXXeWsWoRtOCBh3r3XD+S+jKD3GHutuGrOyh6x+UIgMBNLlXQ6vT1Ixw6gbHRajMfSwfM7CjVJbaw0itGsmo7AUDGQIh2d3ZKBrkdLNW7xlmLS65PBQZKx0UPb/6bphRsBUy0/gcSIQSkp4bIZ4aqtyoDdjNTpG6xt9GqmyZMmc66/CFWFSH7UXlptdwc3/zOfhdcRtKvKAYAsI/bXVCmZKiDOOY3uhi2ODq+5VMO2nNsPQFjSFJfKkhCN9xIR++OiAq0zkCKYDY5Gb22AyQKKsiU+42BUIb8jf7jFU7k6UQFZ0jg3kJi52uJC865wvpqph+96oeHQdWXh0ota65Cs+krh7brvPXQFBiWJjbXfNtW0ybkpXR5oNvBjETtMhx9pwsYtx7aQM= DEBUG: Command: /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmpl_z4fcl6/cert.crt --format PEM --request 0x3de4ca8a80ded6b63d14a2504a1333a0 --profile caAuditSigningCert.profile INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/caAuditSigningCert.profile FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: SecureRandomFactory: Creating secure random: FINE: SecureRandomFactory: - algorithm: pkcs11prng FINE: SecureRandomFactory: - provider: Mozilla-JSS FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: registered: false INFO: DBSubsystem: Configuring excluded LDAP attributes FINE: DBSubsystem: excludedLdapAttrs.enabled: false FINE: CertificateRepository: number radix 16 FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: random FINE: CertificateRepository: - cert ID length: 128 INFO: Creating cert record 0xbc8022f916c5254e07ca3af453fc74d5: INFO: - subject: CN=CA Audit,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: - request ID: 0x3de4ca8a80ded6b63d14a2504a1333a0 INFO: - profile ID mapping: caAuditSigningCert FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 FINE: CertificateRepository: Adding certificate record cn=250560186542242637020483009172029076693,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=CA Audit,O=UFREEIPA.TEST FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=250560186542242637020483009172029076693,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: DateMapper: - value: Wed May 07 18:04:08 UTC 2025 FINE: DateMapper: - database value: 20250507180408Z FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:04:08 UTC 2025 FINE: DateMapper: - database value: 20250507180408Z FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 INFO: Updating request record 0x3de4ca8a80ded6b63d14a2504a1333a0 FINE: CertificateRepository: number radix 10 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: random FINE: RequestRepository: - request ID length: 128 FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Retrieving cn=82270859446735650289564102288330666912,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: DateMapper: Mapping dateOfCreate to requestCreateTime FINE: DateMapper: - database value: 20250507180404Z FINE: DateMapper: - value: Wed May 07 18:04:04 UTC 2025 FINE: DateMapper: Mapping dateOfModify to requestModifyTime FINE: DateMapper: - database value: 20250507180406Z FINE: DateMapper: - value: Wed May 07 18:04:06 UTC 2025 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: CertRequestRepository: Updating cert for request 0x3de4ca8a80ded6b63d14a2504a1333a0 FINE: CertRequestRepository: - cert serial number: 0xbc8022f916c5254e07ca3af453fc74d5 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Modifying cn=82270859446735650289564102288330666912,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:04:10 UTC 2025 FINE: DateMapper: - database value: 20250507180410Z FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(DBSubsystem) INFO: Setting up trust flags DEBUG: Command: certutil -M -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpnzktmcrb/password.txt -n caSigningCert cert-pki-ca -t CTu,Cu,Cu DEBUG: Command: certutil -M -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpnzktmcrb/password.txt -n auditSigningCert cert-pki-ca -t u,u,Pu INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: Validate system certs INFO: Validate signing cert DEBUG: PKISubsystem.get_subsystem_cert(signing) DEBUG: PKISubsystem.get_cert_info(signing) DEBUG: PKISubsystem.get_nssdb_cert_info(signing) DEBUG: NSSDatabase.get_cert_info(caSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(caSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmp7j_xnmmg/password.txt -n caSigningCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(caSigningCert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(caSigningCert cert-pki-ca) DEBUG: fullname: caSigningCert cert-pki-ca DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpb5i25316/password.txt DEBUG: stdout: -1 DEBUG: NSSDatabase.get_cert_info(caSigningCert cert-pki-ca) ends DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf client-cert-validate --certusage SSLCA caSigningCert cert-pki-ca DEBUG: signing certificate is valid INFO: Validate ocsp_signing cert DEBUG: PKISubsystem.get_subsystem_cert(ocsp_signing) DEBUG: PKISubsystem.get_cert_info(ocsp_signing) DEBUG: PKISubsystem.get_nssdb_cert_info(ocsp_signing) DEBUG: NSSDatabase.get_cert_info(ocspSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(ocspSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpu8gfvmg_/password.txt -n ocspSigningCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(ocspSigningCert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(ocspSigningCert cert-pki-ca) DEBUG: fullname: ocspSigningCert cert-pki-ca DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpwm5q6raj/password.txt DEBUG: stdout: -1 DEBUG: NSSDatabase.get_cert_info(ocspSigningCert cert-pki-ca) ends DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf client-cert-validate --certusage StatusResponder ocspSigningCert cert-pki-ca DEBUG: ocsp_signing certificate is valid INFO: Validate audit_signing cert DEBUG: PKISubsystem.get_subsystem_cert(audit_signing) DEBUG: PKISubsystem.get_cert_info(audit_signing) DEBUG: PKISubsystem.get_nssdb_cert_info(audit_signing) DEBUG: NSSDatabase.get_cert_info(auditSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(auditSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpme5xmat8/password.txt -n auditSigningCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(auditSigningCert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(auditSigningCert cert-pki-ca) DEBUG: fullname: auditSigningCert cert-pki-ca DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpu0huze6r/password.txt DEBUG: stdout: -1 DEBUG: NSSDatabase.get_cert_info(auditSigningCert cert-pki-ca) ends DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf client-cert-validate --certusage ObjectSigner auditSigningCert cert-pki-ca DEBUG: audit_signing certificate is valid INFO: Validate sslserver cert DEBUG: PKISubsystem.get_subsystem_cert(sslserver) DEBUG: PKISubsystem.get_cert_info(sslserver) DEBUG: PKISubsystem.get_nssdb_cert_info(sslserver) DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpdv_vlte1/password.txt -n Server-Cert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(Server-Cert cert-pki-ca) DEBUG: fullname: Server-Cert cert-pki-ca DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmp69yklp6j/password.txt DEBUG: stdout: -1 DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) ends DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf client-cert-validate --certusage SSLServer Server-Cert cert-pki-ca DEBUG: sslserver certificate is valid INFO: Validate subsystem cert DEBUG: PKISubsystem.get_subsystem_cert(subsystem) DEBUG: PKISubsystem.get_cert_info(subsystem) DEBUG: PKISubsystem.get_nssdb_cert_info(subsystem) DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpbf2av3e6/password.txt -n subsystemCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(subsystemCert cert-pki-ca) DEBUG: fullname: subsystemCert cert-pki-ca DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpk_8sr103/password.txt DEBUG: stdout: -1 DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) ends DEBUG: Command: pki -d /var/lib/pki/pki-tomcat/conf/alias -f /var/lib/pki/pki-tomcat/conf/password.conf client-cert-validate --certusage SSLClient subsystemCert cert-pki-ca DEBUG: subsystem certificate is valid INFO: Setting up subsystem user INFO: Adding user CA-master.ufreeipa.test-8443 DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-add --full-name CA-master.ufreeipa.test-8443 --type agentType --state 1 --ignore-duplicate --debug CA-master.ufreeipa.test-8443 INFO: Adding certificate for CA-master.ufreeipa.test-8443 DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-cert-add --format PEM --ignore-duplicate --debug CA-master.ufreeipa.test-8443 INFO: Adding CA-master.ufreeipa.test-8443 into Subsystem Group DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Subsystem Group CA-master.ufreeipa.test-8443 INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Subsystem Group,ou=Groups,o=ipaca FINE: description: Subsystem Group FINE: uniqueMember: uid=CA-master.ufreeipa.test-8443,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Creating new security domain INFO: Setting securitydomain.select to new INFO: Setting securitydomain.name to IPA DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-sd-create --debug --name IPA INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 INFO: Adding ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityDomain FINE: - name: IPA FINE: - ou: Security Domain INFO: Adding cn=CAList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: CAList INFO: Adding cn=OCSPList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: OCSPList INFO: Adding cn=KRAList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: KRAList INFO: Adding cn=RAList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: RAList INFO: Adding cn=TKSList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: TKSList INFO: Adding cn=TPSList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: TPSList INFO: Adding security domain manager DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-sd-subsystem-add --subsystem CA --hostname master.ufreeipa.test --unsecure-port 80 --secure-port 443 --domain-manager --debug CA master.ufreeipa.test 8443 INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 INFO: Adding cn=master.ufreeipa.test:443,cn=CAList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSubsystem FINE: - cn: master.ufreeipa.test:443 FINE: - SubsystemName: CA master.ufreeipa.test 8443 FINE: - Host: master.ufreeipa.test FINE: - UnSecurePort: 80 FINE: - SecurePort: 443 FINE: - SecureAgentPort: 443 FINE: - SecureAdminPort: 443 FINE: - SecureEEClientAuthPort: 443 FINE: - DomainManager: TRUE FINE: - Clone: FALSE INFO: Adding security domain sessions INFO: Setting securitydomain.checkIP to false INFO: Setting securitydomain.checkinterval to 300000 INFO: Setting securitydomain.flushinterval to 86400000 INFO: Setting securitydomain.source to ldap INFO: Setting up admin cert DEBUG: PKIDeployer.setup_admin_cert() INFO: Checking admin cert in /root/.dogtag/pki-tomcat/ca/alias DEBUG: NSSDatabase.get_cert_info(ipa-ca-agent) begins DEBUG: NSSDatabase.get_cert(ipa-ca-agent) begins DEBUG: Command: certutil -L -d /root/.dogtag/pki-tomcat/ca/alias -f /root/.dogtag/pki-tomcat/ca/password.conf -n ipa-ca-agent -a DEBUG: stdout: -1 DEBUG: NSSDatabase: stderr: certutil: Could not find cert: ipa-ca-agent : PR_FILE_NOT_FOUND_ERROR: File not found DEBUG: Cert not found: ipa-ca-agent INFO: Checking admin cert in /root/ca-agent.p12 INFO: Checking admin cert in None INFO: Checking admin cert in /root/.dogtag/pki-tomcat/ca_admin.cert INFO: Creating admin cert request INFO: Generating admin CSR in /root/.dogtag/pki-tomcat/ca/alias/admin.csr DEBUG: generate_csr: pki_hsm_enable: False DEBUG: generate_csr: subsystem type: CA DEBUG: Command: pki -d /root/.dogtag/pki-tomcat/ca/alias -C /root/.dogtag/pki-tomcat/ca/password.conf nss-cert-request --subject cn=ipa-ca-agent,O=UFREEIPA.TEST --csr /tmp/tmp5j7uxlpd/admin.csr --key-type RSA --key-size 2048 --hash SHA256 --debug FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: NSSDatabase: Creating RSA key FINE: NSSDatabase: - size: 2048 FINE: CryptoUtil: Generating KRA key pair FINE: CryptoUtil: - temporary: null FINE: CryptoUtil: - sensitive: null FINE: CryptoUtil: - extractable: null FINE: CryptoUtil: generateRSAKeyPair with key usage FINE: CryptoUtil: generateRSAKeyPair with key usage mask FINE: CryptoUtil: - key size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=ipa-ca-agent,O=UFREEIPA.TEST FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=ipa-ca-agent,O=UFREEIPA.TEST FINE: CryptoUtil: - attributes: INFO: Copying /root/.dogtag/pki-tomcat/ca/alias/admin.csr to /var/lib/pki/pki-tomcat/conf/certs/ca_admin.csr DEBUG: Command: cp /root/.dogtag/pki-tomcat/ca/alias/admin.csr /var/lib/pki/pki-tomcat/conf/certs/ca_admin.csr INFO: Getting admin cert from local CA INFO: Loading /var/lib/pki/pki-tomcat/conf/ca/profiles/ca/caAdminCert.cfg INFO: Key type: RSA INFO: Allowed signing algorithms: SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC,SHA256withRSA/PSS,SHA384withRSA/PSS,SHA512withRSA/PSS INFO: Signing algorithm: SHA256withRSA INFO: Importing admin cert request into CA database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --type pkcs10 --profile adminCert.profile --output-format json INFO: - request ID: 0xa0c89db39905c38671d2ea2fefc65f85 INFO: Creating admin cert DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-create --debug --request 0xa0c89db39905c38671d2ea2fefc65f85 --profile adminCert.profile --type local --key-algorithm SHA256withRSA --signing-algorithm SHA256withRSA --format DER INFO: - serial: 0xbbb9509f4f6b7339b493470d571ee07c INFO: Importing admin cert into CA database DEBUG: - cert: MIIEBzCCAm+gAwIBAgIRALu5UJ9Pa3M5tJNHDVce4HwwDQYJKoZIhvcNAQELBQAwODEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTI1MDUwNzE4MDQyNVoXDTI3MDQyNzE4MDQyNVowLzEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEVMBMGA1UEAwwMaXBhLWNhLWFnZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu8RbTYFjFwfoYZCS7+MQWwrBLm18pL4zjLTfY60IcQD42k3xnzH8qPH6bmMe4WOAJSlQE8tGitE26ZMjtKdg1+kzBpZyyDBwl/GX1YvA2U4zJie9KWwNZ/naxlPIlqN3i448sKeQ/2eRemOfA0mtpBbiyY+k9VnjltIs1c7iuBVvaKE4dO50ar5kvGBWlLA/OhxHdcJwHKGctzLWr8L2J5fX1VJ5hLE3jb4eciAYNJuYs6mTBJphkIdrs7+97vhZgbwPJ+27OozEuxWgTpGndtjbGLVCcvOzpYMb/3o8EfE9mhu7D2kE8FgP3B0LGqvu3cWjFLc28ceNY6LN/ouzdwIDAQABo4GUMIGRMB8GA1UdIwQYMBaAFAb4otKUM95HEMV4ddBDTIlHqY1sMD8GCCsGAQUFBwEBBDMwMTAvBggrBgEFBQcwAYYjaHR0cDovL2lwYS1jYS51ZnJlZWlwYS50ZXN0L2NhL29jc3AwDgYDVR0PAQH/BAQDAgXgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDBDANBgkqhkiG9w0BAQsFAAOCAYEAAYwmpFd+UM0s9Zka+fp4xmhTa3WofB8Rodf2YZZdRbpEiOXel6FQOHzhy90FlWdoiiE7mF/YEoQlinN3cmeCu4aMUFg4NaEVGDP5aJzKfPgli9alZSqNe9WQHTwZ4nZBHZYP0ZNS2xD9jFu6VcNmr1Wa0PGD8Xdh2WCW+7RsPUq2blbQgwx+RLSvp+oUppgYDqx/GL/xA5ZxHdLDLbaE4U1y4L1T+PllvnKFDSaM/EGaWeRWs4HtUKI8HdPV8uKOgDexliIPyE/tBJ74ty16+xYiP1YCarfYE7VpSicep/Ejlsb230MLDaWin0pn+eIsnlR2+Mf/1s4fyz0jBDQRKoYtTI/BdXZKfEaTPfL8lcH+A5D+HhhKp6uA9qXN9e293VkjJoImO0UNmMcXnNDrdhcCCUJOGb4Ui0JteaTRyNFxqGFh9mEyXvzqmvcDYRjaPJJDubzaOLTsmMsXLxj2oNeDVS4IYQz32y96xwqWacqHPalbFOzOesexAzZf7gO3 DEBUG: Command: /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmprow4aw1u/cert.crt --format PEM --request 0xa0c89db39905c38671d2ea2fefc65f85 --profile adminCert.profile INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/adminCert.profile FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: SecureRandomFactory: Creating secure random: FINE: SecureRandomFactory: - algorithm: pkcs11prng FINE: SecureRandomFactory: - provider: Mozilla-JSS FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: registered: false INFO: DBSubsystem: Configuring excluded LDAP attributes FINE: DBSubsystem: excludedLdapAttrs.enabled: false FINE: CertificateRepository: number radix 16 FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: random FINE: CertificateRepository: - cert ID length: 128 INFO: Creating cert record 0xbbb9509f4f6b7339b493470d571ee07c: INFO: - subject: CN=ipa-ca-agent,O=UFREEIPA.TEST INFO: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST INFO: - request ID: 0xa0c89db39905c38671d2ea2fefc65f85 INFO: - profile ID mapping: caAdminCert FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 FINE: CertificateRepository: Adding certificate record cn=249527845345233558221160445079541702780,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=ipa-ca-agent,O=UFREEIPA.TEST FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=UFREEIPA.TEST FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=249527845345233558221160445079541702780,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: DateMapper: - value: Wed May 07 18:04:27 UTC 2025 FINE: DateMapper: - database value: 20250507180427Z FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:04:27 UTC 2025 FINE: DateMapper: - database value: 20250507180427Z FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 INFO: Updating request record 0xa0c89db39905c38671d2ea2fefc65f85 FINE: CertificateRepository: number radix 10 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: random FINE: RequestRepository: - request ID length: 128 FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Retrieving cn=213718137264800543029181827355181997957,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: DateMapper: Mapping dateOfCreate to requestCreateTime FINE: DateMapper: - database value: 20250507180423Z FINE: DateMapper: - value: Wed May 07 18:04:23 UTC 2025 FINE: DateMapper: Mapping dateOfModify to requestModifyTime FINE: DateMapper: - database value: 20250507180425Z FINE: DateMapper: - value: Wed May 07 18:04:25 UTC 2025 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: CertRequestRepository: Updating cert for request 0xa0c89db39905c38671d2ea2fefc65f85 FINE: CertRequestRepository: - cert serial number: 0xbbb9509f4f6b7339b493470d571ee07c FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory (DBSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (DBSubsystem).getConn: final values. Total: 1, pool: 0 INFO: LDAPSession: Modifying cn=213718137264800543029181827355181997957,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: DateMapper: - value: Wed May 07 18:04:28 UTC 2025 FINE: DateMapper: - database value: 20250507180428Z FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory (DBSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (DBSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(DBSubsystem) DEBUG: Admin cert: -----BEGIN CERTIFICATE----- MIIEBzCCAm+gAwIBAgIRALu5UJ9Pa3M5tJNHDVce4HwwDQYJKoZIhvcNAQELBQAw ODEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUg QXV0aG9yaXR5MB4XDTI1MDUwNzE4MDQyNVoXDTI3MDQyNzE4MDQyNVowLzEWMBQG A1UECgwNVUZSRUVJUEEuVEVTVDEVMBMGA1UEAwwMaXBhLWNhLWFnZW50MIIBIjAN BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu8RbTYFjFwfoYZCS7+MQWwrBLm18 pL4zjLTfY60IcQD42k3xnzH8qPH6bmMe4WOAJSlQE8tGitE26ZMjtKdg1+kzBpZy yDBwl/GX1YvA2U4zJie9KWwNZ/naxlPIlqN3i448sKeQ/2eRemOfA0mtpBbiyY+k 9VnjltIs1c7iuBVvaKE4dO50ar5kvGBWlLA/OhxHdcJwHKGctzLWr8L2J5fX1VJ5 hLE3jb4eciAYNJuYs6mTBJphkIdrs7+97vhZgbwPJ+27OozEuxWgTpGndtjbGLVC cvOzpYMb/3o8EfE9mhu7D2kE8FgP3B0LGqvu3cWjFLc28ceNY6LN/ouzdwIDAQAB o4GUMIGRMB8GA1UdIwQYMBaAFAb4otKUM95HEMV4ddBDTIlHqY1sMD8GCCsGAQUF BwEBBDMwMTAvBggrBgEFBQcwAYYjaHR0cDovL2lwYS1jYS51ZnJlZWlwYS50ZXN0 L2NhL29jc3AwDgYDVR0PAQH/BAQDAgXgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggr BgEFBQcDBDANBgkqhkiG9w0BAQsFAAOCAYEAAYwmpFd+UM0s9Zka+fp4xmhTa3Wo fB8Rodf2YZZdRbpEiOXel6FQOHzhy90FlWdoiiE7mF/YEoQlinN3cmeCu4aMUFg4 NaEVGDP5aJzKfPgli9alZSqNe9WQHTwZ4nZBHZYP0ZNS2xD9jFu6VcNmr1Wa0PGD 8Xdh2WCW+7RsPUq2blbQgwx+RLSvp+oUppgYDqx/GL/xA5ZxHdLDLbaE4U1y4L1T +PllvnKFDSaM/EGaWeRWs4HtUKI8HdPV8uKOgDexliIPyE/tBJ74ty16+xYiP1YC arfYE7VpSicep/Ejlsb230MLDaWin0pn+eIsnlR2+Mf/1s4fyz0jBDQRKoYtTI/B dXZKfEaTPfL8lcH+A5D+HhhKp6uA9qXN9e293VkjJoImO0UNmMcXnNDrdhcCCUJO Gb4Ui0JteaTRyNFxqGFh9mEyXvzqmvcDYRjaPJJDubzaOLTsmMsXLxj2oNeDVS4I YQz32y96xwqWacqHPalbFOzOesexAzZf7gO3 -----END CERTIFICATE----- INFO: Importing admin cert into /root/.dogtag/pki-tomcat/ca/alias DEBUG: NSSDatabase.import_cert_chain(ipa-ca-agent) begins DEBUG: NSSDatabase: Cert chain: -----BEGIN CERTIFICATE----- MIIEBzCCAm+gAwIBAgIRALu5UJ9Pa3M5tJNHDVce4HwwDQYJKoZIhvcNAQELBQAw ODEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUg QXV0aG9yaXR5MB4XDTI1MDUwNzE4MDQyNVoXDTI3MDQyNzE4MDQyNVowLzEWMBQG A1UECgwNVUZSRUVJUEEuVEVTVDEVMBMGA1UEAwwMaXBhLWNhLWFnZW50MIIBIjAN BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu8RbTYFjFwfoYZCS7+MQWwrBLm18 pL4zjLTfY60IcQD42k3xnzH8qPH6bmMe4WOAJSlQE8tGitE26ZMjtKdg1+kzBpZy yDBwl/GX1YvA2U4zJie9KWwNZ/naxlPIlqN3i448sKeQ/2eRemOfA0mtpBbiyY+k 9VnjltIs1c7iuBVvaKE4dO50ar5kvGBWlLA/OhxHdcJwHKGctzLWr8L2J5fX1VJ5 hLE3jb4eciAYNJuYs6mTBJphkIdrs7+97vhZgbwPJ+27OozEuxWgTpGndtjbGLVC cvOzpYMb/3o8EfE9mhu7D2kE8FgP3B0LGqvu3cWjFLc28ceNY6LN/ouzdwIDAQAB o4GUMIGRMB8GA1UdIwQYMBaAFAb4otKUM95HEMV4ddBDTIlHqY1sMD8GCCsGAQUF BwEBBDMwMTAvBggrBgEFBQcwAYYjaHR0cDovL2lwYS1jYS51ZnJlZWlwYS50ZXN0 L2NhL29jc3AwDgYDVR0PAQH/BAQDAgXgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggr BgEFBQcDBDANBgkqhkiG9w0BAQsFAAOCAYEAAYwmpFd+UM0s9Zka+fp4xmhTa3Wo fB8Rodf2YZZdRbpEiOXel6FQOHzhy90FlWdoiiE7mF/YEoQlinN3cmeCu4aMUFg4 NaEVGDP5aJzKfPgli9alZSqNe9WQHTwZ4nZBHZYP0ZNS2xD9jFu6VcNmr1Wa0PGD 8Xdh2WCW+7RsPUq2blbQgwx+RLSvp+oUppgYDqx/GL/xA5ZxHdLDLbaE4U1y4L1T +PllvnKFDSaM/EGaWeRWs4HtUKI8HdPV8uKOgDexliIPyE/tBJ74ty16+xYiP1YC arfYE7VpSicep/Ejlsb230MLDaWin0pn+eIsnlR2+Mf/1s4fyz0jBDQRKoYtTI/B dXZKfEaTPfL8lcH+A5D+HhhKp6uA9qXN9e293VkjJoImO0UNmMcXnNDrdhcCCUJO Gb4Ui0JteaTRyNFxqGFh9mEyXvzqmvcDYRjaPJJDubzaOLTsmMsXLxj2oNeDVS4I YQz32y96xwqWacqHPalbFOzOesexAzZf7gO3 -----END CERTIFICATE----- DEBUG: Importing a single cert DEBUG: NSSDatabase.add_cert(ipa-ca-agent) DEBUG: Command: pki -d /root/.dogtag/pki-tomcat/ca/alias -C /root/.dogtag/pki-tomcat/ca/password.conf nss-cert-import --format PEM --trust ,, --debug ipa-ca-agent FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token FINE: Importing cert ipa-ca-agent into internal token DEBUG: NSSDatabase.import_cert_chain(ipa-ca-agent) ends INFO: Storing admin cert into /root/.dogtag/pki-tomcat/ca_admin.cert INFO: Reusing /root DEBUG: NSSDatabase.get_cert(ipa-ca-agent) begins DEBUG: Command: certutil -L -d /root/.dogtag/pki-tomcat/ca/alias -f /root/.dogtag/pki-tomcat/ca/password.conf -n ipa-ca-agent -a DEBUG: stdout: -1 DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(ipa-ca-agent) ends INFO: Exporting admin cert into /root/ca-agent.p12 DEBUG: Command: pki -d /root/.dogtag/pki-tomcat/ca/alias -C /root/.dogtag/pki-tomcat/ca/password.conf pkcs12-export --pkcs12 /root/ca-agent.p12 --password-file /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf --no-chain --debug ipa-ca-agent FINE: Initializing NSS FINE: Logging into internal token FINE: Using internal token INFO: Setting up admin user INFO: Adding user admin DEBUG: Command: /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-add --full-name admin --email root@localhost --password-file /tmp/tmpfbvsicx2/password.txt --type adminType --state 1 --ignore-duplicate --debug admin INFO: Adding admin into Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Administrators admin INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Administrators,ou=Groups,o=ipaca FINE: description: People who manage the Certificate System FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding admin into Certificate Manager Agents DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Certificate Manager Agents admin INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Certificate Manager Agents,ou=Groups,o=ipaca FINE: description: Agents for Certificate Manager FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding admin into Security Domain Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Security Domain Administrators admin INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Security Domain Administrators,ou=Groups,o=ipaca FINE: description: People who are the Security Domain administrators FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding admin into Enterprise CA Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise CA Administrators admin INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Enterprise CA Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for CA FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding admin into Enterprise KRA Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise KRA Administrators admin INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Enterprise KRA Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for KRA FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding admin into Enterprise RA Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise RA Administrators admin INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Enterprise RA Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for RA FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding admin into Enterprise TKS Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise TKS Administrators admin INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Enterprise TKS Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for TKS FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding admin into Enterprise OCSP Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise OCSP Administrators admin INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Enterprise OCSP Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for OCSP FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding admin into Enterprise TPS Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise TPS Administrators admin INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Enterprise TPS Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for TPS FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding certificate for admin DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-cert-add --format PEM --ignore-duplicate --debug admin INFO: Setting up database user INFO: Adding user pkidbuser DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-add --full-name pkidbuser --type agentType --state 1 --attributes nsPagedSizeLimit:20000 --ignore-duplicate --debug pkidbuser DEBUG: PKISubsystem.get_subsystem_cert(subsystem) DEBUG: PKISubsystem.get_cert_info(subsystem) DEBUG: PKISubsystem.get_nssdb_cert_info(subsystem) DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmp706wdpv6/password.txt -n subsystemCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(subsystemCert cert-pki-ca) DEBUG: fullname: subsystemCert cert-pki-ca DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmpucnpcyha/password.txt DEBUG: stdout: -1 DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) ends DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /var/lib/pki/pki-tomcat/conf/alias -f /tmp/tmp9z_v07z6/password.txt -n subsystemCert cert-pki-ca -a DEBUG: stdout: -1 DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) ends INFO: Adding subsystem cert into pkidbuser DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-cert-add --format PEM --ignore-duplicate --debug pkidbuser INFO: Linking pkidbuser to subsystem cert: CN=CA Subsystem,O=UFREEIPA.TEST DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-mod --add-see-also CN=CA Subsystem,O=UFREEIPA.TEST --debug pkidbuser INFO: Finding other users linked to subsystem cert DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-find --see-also CN=CA Subsystem,O=UFREEIPA.TEST --debug --output-format json INFO: Adding pkidbuser into Subsystem Group DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Subsystem Group pkidbuser INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Subsystem Group,ou=Groups,o=ipaca FINE: description: Subsystem Group FINE: uniqueMember: uid=CA-master.ufreeipa.test-8443,ou=People,o=ipaca FINE: uniqueMember: uid=pkidbuser,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Adding pkidbuser into Certificate Manager Agents DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Certificate Manager Agents pkidbuser INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: Setting internaldb.minConns=0 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 0 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.ufreeipa.test FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: dn: cn=Certificate Manager Agents,ou=Groups,o=ipaca FINE: description: Agents for Certificate Manager FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: uniqueMember: uid=pkidbuser,ou=People,o=ipaca FINE: LdapBoundConnFactory (UGSubsystem).getConn: initial values. Total: 0, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: master connection is null FINE: LdapBoundConnFactory.makeMinimum: master conn not available. FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory: makeNewConnection(true) FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: got password from memory FINE: LdapAuthInfo: init: password found for prompt. FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.ufreeipa.test:389 with basic auth as cn=Directory Manager FINE: PKISocketFactory: Creating socket for master.ufreeipa.test:389 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory (UGSubsystem).getConn: final values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: initial values. Total: 1, pool: 0 FINE: LdapBoundConnFactory (UGSubsystem).returnConn: final values. Total: 0, pool: 0 FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Enabling CRL INFO: Setting ca.crl.MasterCRL.enable to true INFO: Updating CA ranges DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-21-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-range-update --debug INFO: TomcatJSS: Loading JSS configuration from /var/lib/pki/pki-tomcat/conf/server.xml INFO: TomcatJSS: initialization FINE: TomcatJSS: certdbDir: /var/lib/pki/pki-tomcat/conf/alias FINE: TomcatJSS: passwordClass: org.dogtagpki.jss.tomcat.PlainPasswordFile FINE: TomcatJSS: passwordFile: /var/lib/pki/pki-tomcat/conf/password.conf FINE: TomcatJSS: serverCertNickFile: /var/lib/pki/pki-tomcat/conf/serverCertNick.conf FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: TomcatJSS: logging into tokens FINE: TomcatJSS: logging into internal FINE: serverCertNick: Server-Cert cert-pki-ca FINE: clientAuth: want FINE: requireClientAuth: false FINE: wantClientAuth: true INFO: configuring Revocation Check FINE: enableRevocationCheck: false INFO: TomcatJSS: initialization complete FINE: CARangeUpdateCLI: Loading /var/lib/pki/pki-tomcat/conf/ca/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: PKISocketFactory: Initializing PKISocketFactory FINE: PKISocketFactory: - keep alive: true FINE: PKISocketFactory: - client ciphers: INFO: No need to update certificate ID range INFO: No need to update request ID range INFO: Starting CRL number: 0 INFO: Setting ca.crl.MasterCRL.startingCrlNumber to 0 INFO: Enabling profile subsystem INFO: Setting subsystem.1.enabled to true INFO: Setting jss.ssl.sslserver.ectype to ECDHE INFO: Setting cs.state to 1 INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: CA configuration complete INFO: Updating /var/lib/pki/pki-tomcat/conf/serverCertNick.conf INFO: Updating serverCertNickFile in server.xml INFO: Finalizing subsystem creation INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /var/lib/pki/pki-tomcat/conf/tomcat.conf INFO: Loading password config: /var/lib/pki/pki-tomcat/conf/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/conf/ca/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Loading external certs from /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: File does not exist: /var/lib/pki/pki-tomcat/conf/external_certs.conf INFO: Backing up keys into /var/lib/pki/pki-tomcat/conf/alias/ca_backup_keys.p12 DEBUG: Command: pki-server subsystem-cert-export ca -i pki-tomcat --pkcs12-file /var/lib/pki/pki-tomcat/conf/alias/ca_backup_keys.p12 --pkcs12-password-file /tmp/tmph_hsn7u7/password.txt DEBUG: Command: systemctl enable pki-tomcatd@pki-tomcat.service INFO: Starting PKI server DEBUG: Command: systemctl start pki-tomcatd@pki-tomcat.service INFO: Waiting for PKI server to start DEBUG: Starting new HTTPS connection (1): master.ufreeipa.test:8443 INFO: Waiting for PKI server to start (1s) DEBUG: Starting new HTTPS connection (1): master.ufreeipa.test:8443 DEBUG: https://master.ufreeipa.test:8443 "GET / HTTP/1.1" 200 3500 INFO: PKI server started INFO: Waiting for CA subsystem DEBUG: Starting new HTTPS connection (1): master.ufreeipa.test:8443 DEBUG: https://master.ufreeipa.test:8443 "GET /ca/admin/ca/getStatus HTTP/1.1" 200 122 INFO: Subsystem status: running DEBUG: Command: rm -rf /root/.dogtag/pki-tomcat/ca INFO: END spawning CA subsystem in pki-tomcat instance INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat/ca/deployment.cfg INFO: Creating /var/lib/pki/pki-tomcat/logs/ca/archive/spawn_deployment.cfg.20250507180238 INFO: Copying /etc/sysconfig/pki/tomcat/pki-tomcat/ca/deployment.cfg to /var/lib/pki/pki-tomcat/logs/ca/archive/spawn_deployment.cfg.20250507180238 DEBUG: Command: cp /etc/sysconfig/pki/tomcat/pki-tomcat/ca/deployment.cfg /var/lib/pki/pki-tomcat/logs/ca/archive/spawn_deployment.cfg.20250507180238 INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat/ca/manifest INFO: Creating /var/lib/pki/pki-tomcat/logs/ca/archive/spawn_manifest.20250507180238 INFO: Copying /etc/sysconfig/pki/tomcat/pki-tomcat/ca/manifest to /var/lib/pki/pki-tomcat/logs/ca/archive/spawn_manifest.20250507180238 DEBUG: Command: cp /etc/sysconfig/pki/tomcat/pki-tomcat/ca/manifest /var/lib/pki/pki-tomcat/logs/ca/archive/spawn_manifest.20250507180238 2025-05-07T18:05:15Z DEBUG completed creating ca instance 2025-05-07T18:05:15Z DEBUG step duration: pki-tomcatd __spawn_instance 157.30 sec 2025-05-07T18:05:15Z DEBUG [2/33]: stopping certificate server instance to update CS.cfg 2025-05-07T18:05:15Z DEBUG Starting external process 2025-05-07T18:05:15Z DEBUG args=['/bin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2025-05-07T18:05:16Z DEBUG Process finished, return code=0 2025-05-07T18:05:16Z DEBUG stdout= 2025-05-07T18:05:16Z DEBUG stderr= 2025-05-07T18:05:16Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2025-05-07T18:05:16Z DEBUG step duration: pki-tomcatd stop_instance 0.73 sec 2025-05-07T18:05:16Z DEBUG [3/33]: backing up CS.cfg 2025-05-07T18:05:16Z DEBUG Starting external process 2025-05-07T18:05:16Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2025-05-07T18:05:16Z DEBUG Process finished, return code=3 2025-05-07T18:05:16Z DEBUG stdout=inactive 2025-05-07T18:05:16Z DEBUG stderr= 2025-05-07T18:05:16Z DEBUG step duration: pki-tomcatd safe_backup_config 0.01 sec 2025-05-07T18:05:16Z DEBUG [4/33]: Add ipa-pki-wait-running 2025-05-07T18:05:16Z DEBUG Starting external process 2025-05-07T18:05:16Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2025-05-07T18:05:16Z DEBUG Process finished, return code=0 2025-05-07T18:05:16Z DEBUG stdout= 2025-05-07T18:05:16Z DEBUG stderr= 2025-05-07T18:05:16Z INFO Set start up timeout of pki-tomcatd service to 90 seconds 2025-05-07T18:05:16Z DEBUG step duration: pki-tomcatd add_ipa_wait 0.31 sec 2025-05-07T18:05:16Z DEBUG [5/33]: secure AJP connector 2025-05-07T18:05:16Z DEBUG Starting external process 2025-05-07T18:05:16Z DEBUG args=['/usr/sbin/tomcat', 'version'] 2025-05-07T18:05:16Z DEBUG Process finished, return code=0 2025-05-07T18:05:16Z DEBUG stdout=Server version: Apache Tomcat/9.0.104 Server built: Apr 9 2025 00:00:00 UTC Server number: 9.0.104.0 OS Name: Linux OS Version: 6.14.0-63.fc42.x86_64 Architecture: amd64 JVM Version: 21.0.7+6 JVM Vendor: Red Hat, Inc. 2025-05-07T18:05:16Z DEBUG stderr=NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=java.base/java.util=ALL-UNNAMED --add-opens=java.base/java.util.concurrent=ALL-UNNAMED --add-opens=java.rmi/sun.rmi.transport=ALL-UNNAMED 2025-05-07T18:05:16Z DEBUG Starting external process 2025-05-07T18:05:16Z DEBUG args=['/usr/sbin/tomcat', 'version'] 2025-05-07T18:05:16Z DEBUG Process finished, return code=0 2025-05-07T18:05:16Z DEBUG stdout=Server version: Apache Tomcat/9.0.104 Server built: Apr 9 2025 00:00:00 UTC Server number: 9.0.104.0 OS Name: Linux OS Version: 6.14.0-63.fc42.x86_64 Architecture: amd64 JVM Version: 21.0.7+6 JVM Vendor: Red Hat, Inc. 2025-05-07T18:05:16Z DEBUG stderr=NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=java.base/java.util=ALL-UNNAMED --add-opens=java.base/java.util.concurrent=ALL-UNNAMED --add-opens=java.rmi/sun.rmi.transport=ALL-UNNAMED 2025-05-07T18:05:16Z DEBUG step duration: pki-tomcatd secure_ajp_connector 0.20 sec 2025-05-07T18:05:16Z DEBUG [6/33]: reindex attributes 2025-05-07T18:05:16Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:05:16Z DEBUG Creating ipaca reindex task cn=indextask_ipaca_1746641116,cn=index,cn=tasks,cn=config 2025-05-07T18:05:16Z DEBUG Waiting for task... 2025-05-07T18:05:18Z DEBUG Task cn=indextask_ipaca_1746641116,cn=index,cn=tasks,cn=config has finished with exit code 0 2025-05-07T18:05:18Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:05:18Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:05:18Z DEBUG step duration: pki-tomcatd reindex_task 2.04 sec 2025-05-07T18:05:18Z DEBUG [7/33]: exporting Dogtag certificate store pin 2025-05-07T18:05:18Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:05:18Z DEBUG step duration: pki-tomcatd create_certstore_passwdfile 0.00 sec 2025-05-07T18:05:18Z DEBUG [8/33]: disabling nonces 2025-05-07T18:05:18Z DEBUG step duration: pki-tomcatd __disable_nonce 0.00 sec 2025-05-07T18:05:18Z DEBUG [9/33]: set up CRL publishing 2025-05-07T18:05:18Z DEBUG Starting external process 2025-05-07T18:05:18Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:05:18Z DEBUG Process finished, return code=0 2025-05-07T18:05:18Z DEBUG stdout= 2025-05-07T18:05:18Z DEBUG stderr= 2025-05-07T18:05:18Z DEBUG Starting external process 2025-05-07T18:05:18Z DEBUG args=['/sbin/restorecon', '/var/lib/ipa/pki-ca/publish'] 2025-05-07T18:05:18Z DEBUG Process finished, return code=0 2025-05-07T18:05:18Z DEBUG stdout= 2025-05-07T18:05:18Z DEBUG stderr= 2025-05-07T18:05:18Z DEBUG step duration: pki-tomcatd __enable_crl_publish 0.08 sec 2025-05-07T18:05:18Z DEBUG [10/33]: enable PKIX certificate path discovery and validation 2025-05-07T18:05:18Z DEBUG step duration: pki-tomcatd enable_pkix 0.00 sec 2025-05-07T18:05:18Z DEBUG [11/33]: authorizing RA to modify profiles 2025-05-07T18:05:18Z DEBUG update_entry modlist [(0, 'resourceACLS', [b'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles'])] 2025-05-07T18:05:18Z DEBUG step duration: pki-tomcatd configure_profiles_acl 0.03 sec 2025-05-07T18:05:18Z DEBUG [12/33]: authorizing RA to manage lightweight CAs 2025-05-07T18:05:18Z DEBUG update_entry modlist [(0, 'resourceACLS', [b'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities'])] 2025-05-07T18:05:18Z DEBUG step duration: pki-tomcatd configure_lightweight_ca_acls 0.02 sec 2025-05-07T18:05:18Z DEBUG [13/33]: Ensure lightweight CAs container exists 2025-05-07T18:05:18Z DEBUG step duration: pki-tomcatd ensure_lightweight_cas_container 0.00 sec 2025-05-07T18:05:18Z DEBUG [14/33]: Enable lightweight CA monitor 2025-05-07T18:05:18Z DEBUG step duration: pki-tomcatd enable_lightweight_ca_monitor 0.00 sec 2025-05-07T18:05:18Z DEBUG [15/33]: Ensuring backward compatibility 2025-05-07T18:05:18Z DEBUG importing all plugin modules in ipaserver.plugins... 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.aci 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.automember 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.automount 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.baseldap 2025-05-07T18:05:18Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.baseuser 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.batch 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.ca 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.caacl 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.cert 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.certmap 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.certprofile 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.config 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.delegation 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.dns 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.dogtag 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.group 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.hbac 2025-05-07T18:05:18Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.hbactest 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.host 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.idp 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.idrange 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.idviews 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.internal 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.join 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.ldap2 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.location 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.migration 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.misc 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.netgroup 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.otp 2025-05-07T18:05:18Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.otptoken 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.passkeyconfig 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.passwd 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.permission 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.ping 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.pkinit 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.privilege 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.rabase 2025-05-07T18:05:18Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.role 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.schema 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.selfservice 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.server 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.serverrole 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.serverroles 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.service 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.session 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.stageuser 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.subid 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.sudo 2025-05-07T18:05:18Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.sudorule 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.topology 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.trust 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.user 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.vault 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.virtual 2025-05-07T18:05:18Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.whoami 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2025-05-07T18:05:18Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.dns 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_subid_support 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2025-05-07T18:05:18Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2025-05-07T18:05:19Z DEBUG Created connection context.ldap2_139937087644960 2025-05-07T18:05:19Z DEBUG raw: idrange_show('UFREEIPA.TEST_id_range', version='2.254') 2025-05-07T18:05:19Z DEBUG idrange_show('UFREEIPA.TEST_id_range', rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:05:19Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:05:19Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:05:19Z DEBUG Parsing update file '/usr/share/ipa/updates/50-dogtag10-migration.update' 2025-05-07T18:05:19Z DEBUG Updating existing entry: cn=aclResources,o=ipaca 2025-05-07T18:05:19Z DEBUG --------------------------------------------- 2025-05-07T18:05:19Z DEBUG Initial value 2025-05-07T18:05:19Z DEBUG dn: cn=aclResources,o=ipaca 2025-05-07T18:05:19Z DEBUG resourceACLS: 2025-05-07T18:05:19Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2025-05-07T18:05:19Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2025-05-07T18:05:19Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2025-05-07T18:05:19Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2025-05-07T18:05:19Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2025-05-07T18:05:19Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2025-05-07T18:05:19Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2025-05-07T18:05:19Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2025-05-07T18:05:19Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2025-05-07T18:05:19Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2025-05-07T18:05:19Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2025-05-07T18:05:19Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2025-05-07T18:05:19Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2025-05-07T18:05:19Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2025-05-07T18:05:19Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2025-05-07T18:05:19Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2025-05-07T18:05:19Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2025-05-07T18:05:19Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2025-05-07T18:05:19Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2025-05-07T18:05:19Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2025-05-07T18:05:19Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2025-05-07T18:05:19Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2025-05-07T18:05:19Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2025-05-07T18:05:19Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2025-05-07T18:05:19Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2025-05-07T18:05:19Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2025-05-07T18:05:19Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2025-05-07T18:05:19Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2025-05-07T18:05:19Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2025-05-07T18:05:19Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2025-05-07T18:05:19Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2025-05-07T18:05:19Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2025-05-07T18:05:19Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2025-05-07T18:05:19Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2025-05-07T18:05:19Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2025-05-07T18:05:19Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2025-05-07T18:05:19Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2025-05-07T18:05:19Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2025-05-07T18:05:19Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2025-05-07T18:05:19Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2025-05-07T18:05:19Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2025-05-07T18:05:19Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2025-05-07T18:05:19Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2025-05-07T18:05:19Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2025-05-07T18:05:19Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2025-05-07T18:05:19Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2025-05-07T18:05:19Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2025-05-07T18:05:19Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2025-05-07T18:05:19Z DEBUG objectClass: 2025-05-07T18:05:19Z DEBUG top 2025-05-07T18:05:19Z DEBUG CertACLS 2025-05-07T18:05:19Z DEBUG cn: 2025-05-07T18:05:19Z DEBUG aclResources 2025-05-07T18:05:19Z DEBUG addifexist: 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities'] 2025-05-07T18:05:19Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2025-05-07T18:05:19Z DEBUG addifexist: 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2025-05-07T18:05:19Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2025-05-07T18:05:19Z DEBUG addifexist: 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2025-05-07T18:05:19Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2025-05-07T18:05:19Z DEBUG addifexist: 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2025-05-07T18:05:19Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2025-05-07T18:05:19Z DEBUG addifexist: 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2025-05-07T18:05:19Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2025-05-07T18:05:19Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group":Anybody is allowed to read domain.xml but only Subsystem group is allowed to modify the domain.xml not found, skipping 2025-05-07T18:05:19Z DEBUG replace: updated value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml'] 2025-05-07T18:05:19Z DEBUG replace: certServer.ca.connectorInfo:read,modify:allow (modify,read) group="Enterprise KRA Administrators":Only Enterprise Administrators are allowed to update the connector information not found, skipping 2025-05-07T18:05:19Z DEBUG addifexist: 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml'] 2025-05-07T18:05:19Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles'] 2025-05-07T18:05:19Z DEBUG --------------------------------------------- 2025-05-07T18:05:19Z DEBUG Final value after applying updates 2025-05-07T18:05:19Z DEBUG dn: cn=aclResources,o=ipaca 2025-05-07T18:05:19Z DEBUG resourceACLS: 2025-05-07T18:05:19Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2025-05-07T18:05:19Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2025-05-07T18:05:19Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2025-05-07T18:05:19Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2025-05-07T18:05:19Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2025-05-07T18:05:19Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2025-05-07T18:05:19Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2025-05-07T18:05:19Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2025-05-07T18:05:19Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2025-05-07T18:05:19Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2025-05-07T18:05:19Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2025-05-07T18:05:19Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2025-05-07T18:05:19Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2025-05-07T18:05:19Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2025-05-07T18:05:19Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2025-05-07T18:05:19Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2025-05-07T18:05:19Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2025-05-07T18:05:19Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2025-05-07T18:05:19Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2025-05-07T18:05:19Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2025-05-07T18:05:19Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2025-05-07T18:05:19Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2025-05-07T18:05:19Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2025-05-07T18:05:19Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2025-05-07T18:05:19Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2025-05-07T18:05:19Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2025-05-07T18:05:19Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2025-05-07T18:05:19Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2025-05-07T18:05:19Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2025-05-07T18:05:19Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2025-05-07T18:05:19Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2025-05-07T18:05:19Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2025-05-07T18:05:19Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2025-05-07T18:05:19Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2025-05-07T18:05:19Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2025-05-07T18:05:19Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2025-05-07T18:05:19Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2025-05-07T18:05:19Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2025-05-07T18:05:19Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2025-05-07T18:05:19Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2025-05-07T18:05:19Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2025-05-07T18:05:19Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2025-05-07T18:05:19Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2025-05-07T18:05:19Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2025-05-07T18:05:19Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2025-05-07T18:05:19Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2025-05-07T18:05:19Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2025-05-07T18:05:19Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2025-05-07T18:05:19Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2025-05-07T18:05:19Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2025-05-07T18:05:19Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2025-05-07T18:05:19Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2025-05-07T18:05:19Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2025-05-07T18:05:19Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2025-05-07T18:05:19Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2025-05-07T18:05:19Z DEBUG objectClass: 2025-05-07T18:05:19Z DEBUG top 2025-05-07T18:05:19Z DEBUG CertACLS 2025-05-07T18:05:19Z DEBUG cn: 2025-05-07T18:05:19Z DEBUG aclResources 2025-05-07T18:05:19Z DEBUG [(1, 'resourceACLS', ['certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml']), (0, 'resourceACLS', ['certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml'])] 2025-05-07T18:05:19Z DEBUG Updated 1 2025-05-07T18:05:19Z DEBUG update_entry modlist [(1, 'resourceACLS', [b'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml']), (0, 'resourceACLS', [b'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml'])] 2025-05-07T18:05:19Z DEBUG Done 2025-05-07T18:05:19Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-dogtag10-migration.update 0.023 sec 2025-05-07T18:05:19Z DEBUG Destroyed connection context.ldap2_139937087644960 2025-05-07T18:05:19Z DEBUG step duration: pki-tomcatd __dogtag10_migration 0.93 sec 2025-05-07T18:05:19Z DEBUG [16/33]: enable certificate pruning 2025-05-07T18:05:19Z DEBUG step duration: pki-tomcatd enable_pruning 0.00 sec 2025-05-07T18:05:19Z DEBUG [17/33]: updating IPA configuration 2025-05-07T18:05:19Z DEBUG step duration: pki-tomcatd update_ipa_conf 0.00 sec 2025-05-07T18:05:19Z DEBUG [18/33]: starting certificate server instance 2025-05-07T18:05:19Z DEBUG Starting external process 2025-05-07T18:05:19Z DEBUG args=['/bin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2025-05-07T18:05:29Z DEBUG Process finished, return code=0 2025-05-07T18:05:29Z DEBUG stdout= 2025-05-07T18:05:29Z DEBUG stderr= 2025-05-07T18:05:29Z DEBUG Starting external process 2025-05-07T18:05:29Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2025-05-07T18:05:29Z DEBUG Process finished, return code=0 2025-05-07T18:05:29Z DEBUG stdout=active 2025-05-07T18:05:29Z DEBUG stderr= 2025-05-07T18:05:29Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 90 2025-05-07T18:05:29Z DEBUG waiting for port: 8080 2025-05-07T18:05:29Z DEBUG SUCCESS: port: 8080 2025-05-07T18:05:29Z DEBUG waiting for port: 8443 2025-05-07T18:05:29Z DEBUG SUCCESS: port: 8443 2025-05-07T18:05:29Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2025-05-07T18:05:29Z DEBUG step duration: pki-tomcatd start_instance 9.43 sec 2025-05-07T18:05:29Z DEBUG [19/33]: configure certmonger for renewals 2025-05-07T18:05:29Z DEBUG Starting external process 2025-05-07T18:05:29Z DEBUG args=['/bin/systemctl', 'enable', 'certmonger.service'] 2025-05-07T18:05:29Z DEBUG Process finished, return code=0 2025-05-07T18:05:29Z DEBUG stdout= 2025-05-07T18:05:29Z DEBUG stderr=Created symlink '/etc/systemd/system/multi-user.target.wants/certmonger.service' → '/usr/lib/systemd/system/certmonger.service'. 2025-05-07T18:05:29Z DEBUG Starting external process 2025-05-07T18:05:29Z DEBUG args=['/bin/systemctl', 'is-active', 'dbus.service'] 2025-05-07T18:05:29Z DEBUG Process finished, return code=0 2025-05-07T18:05:29Z DEBUG stdout=active 2025-05-07T18:05:29Z DEBUG stderr= 2025-05-07T18:05:29Z DEBUG Starting external process 2025-05-07T18:05:29Z DEBUG args=['/bin/systemctl', 'start', 'certmonger.service'] 2025-05-07T18:05:29Z DEBUG Process finished, return code=0 2025-05-07T18:05:29Z DEBUG stdout= 2025-05-07T18:05:29Z DEBUG stderr= 2025-05-07T18:05:29Z DEBUG Starting external process 2025-05-07T18:05:29Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2025-05-07T18:05:29Z DEBUG Process finished, return code=0 2025-05-07T18:05:29Z DEBUG stdout=active 2025-05-07T18:05:29Z DEBUG stderr= 2025-05-07T18:05:29Z DEBUG Start of certmonger.service complete 2025-05-07T18:05:29Z DEBUG step duration: pki-tomcatd configure_certmonger_renewal_helpers 0.83 sec 2025-05-07T18:05:29Z DEBUG [20/33]: requesting RA certificate from CA 2025-05-07T18:05:30Z DEBUG Starting external process 2025-05-07T18:05:30Z DEBUG args=['/usr/bin/openssl', 'pkcs7', '-inform', 'DER', '-print_certs', '-out', '/var/lib/ipa/tmpn58w7btt'] 2025-05-07T18:05:30Z DEBUG Process finished, return code=0 2025-05-07T18:05:30Z DEBUG stdout= 2025-05-07T18:05:30Z DEBUG stderr= 2025-05-07T18:05:30Z DEBUG Starting external process 2025-05-07T18:05:30Z DEBUG args=['/usr/bin/openssl', 'pkcs12', '-nokeys', '-clcerts', '-in', '/root/ca-agent.p12', '-out', '/var/lib/ipa/tmplv6wtlw1', '-passin', 'file:/tmp/tmpw3ha9ti1'] 2025-05-07T18:05:30Z DEBUG Process finished, return code=0 2025-05-07T18:05:30Z DEBUG stdout= 2025-05-07T18:05:30Z DEBUG stderr= 2025-05-07T18:05:30Z DEBUG Starting external process 2025-05-07T18:05:30Z DEBUG args=['/usr/bin/openssl', 'pkcs12', '-nocerts', '-in', '/root/ca-agent.p12', '-out', '/var/lib/ipa/tmpkzm1qi31', '-passin', 'file:/tmp/tmpkmmk6umh', '-nodes'] 2025-05-07T18:05:30Z DEBUG Process finished, return code=0 2025-05-07T18:05:30Z DEBUG stdout= 2025-05-07T18:05:30Z DEBUG stderr= 2025-05-07T18:05:36Z DEBUG certmonger request is in state 'GENERATING_KEY_PAIR' 2025-05-07T18:05:37Z DEBUG certmonger request is in state 'SUBMITTING' 2025-05-07T18:05:37Z DEBUG certmonger request is in state 'PRE_SAVE_CERT' 2025-05-07T18:05:38Z DEBUG certmonger request is in state 'POST_SAVED_CERT' 2025-05-07T18:05:40Z DEBUG certmonger request is in state 'MONITORING' 2025-05-07T18:05:40Z DEBUG Cert request 20250507180536 was successful 2025-05-07T18:05:40Z DEBUG Starting external process 2025-05-07T18:05:40Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:05:40Z DEBUG Process finished, return code=0 2025-05-07T18:05:40Z DEBUG stdout= 2025-05-07T18:05:40Z DEBUG stderr= 2025-05-07T18:05:40Z DEBUG Starting external process 2025-05-07T18:05:40Z DEBUG args=['/sbin/restorecon', '/var/lib/ipa/ra-agent.pem'] 2025-05-07T18:05:40Z DEBUG Process finished, return code=0 2025-05-07T18:05:40Z DEBUG stdout= 2025-05-07T18:05:40Z DEBUG stderr= 2025-05-07T18:05:40Z DEBUG Starting external process 2025-05-07T18:05:40Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:05:40Z DEBUG Process finished, return code=0 2025-05-07T18:05:40Z DEBUG stdout= 2025-05-07T18:05:40Z DEBUG stderr= 2025-05-07T18:05:40Z DEBUG Starting external process 2025-05-07T18:05:40Z DEBUG args=['/sbin/restorecon', '/var/lib/ipa/ra-agent.key'] 2025-05-07T18:05:40Z DEBUG Process finished, return code=0 2025-05-07T18:05:40Z DEBUG stdout= 2025-05-07T18:05:40Z DEBUG stderr= 2025-05-07T18:05:40Z DEBUG step duration: pki-tomcatd __request_ra_certificate 10.07 sec 2025-05-07T18:05:40Z DEBUG [21/33]: publishing the CA certificate 2025-05-07T18:05:40Z DEBUG step duration: pki-tomcatd __export_ca_chain 0.03 sec 2025-05-07T18:05:40Z DEBUG [22/33]: adding RA agent as a trusted user 2025-05-07T18:05:40Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Certificate Manager Agents,ou=groups,o=ipaca member_attr=uniqueMember 2025-05-07T18:05:40Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Registration Manager Agents,ou=groups,o=ipaca member_attr=uniqueMember 2025-05-07T18:05:40Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Security Domain Administrators,ou=groups,o=ipaca member_attr=uniqueMember 2025-05-07T18:05:40Z DEBUG step duration: pki-tomcatd __create_ca_agent 0.18 sec 2025-05-07T18:05:40Z DEBUG [23/33]: configure certificate renewals 2025-05-07T18:05:40Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:40Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:40Z DEBUG start tracking {'TRACK': True, 'CERT_STORAGE': 'NSSDB', 'KEY_STORAGE': 'NSSDB', 'CERT_LOCATION': '/etc/pki/pki-tomcat/alias', 'KEY_LOCATION': '/etc/pki/pki-tomcat/alias', 'CA': dbus.ObjectPath('/org/fedorahosted/certmonger/cas/CA5'), 'CERT_NICKNAME': 'auditSigningCert cert-pki-ca', 'KEY_NICKNAME': 'auditSigningCert cert-pki-ca', 'KEY_PIN': '7My^4a)E?PI(B1T%lZk}97X-nIw~[IPgAZy|9yr2G', 'cert-presave-command': '/usr/libexec/ipa/certmonger/stop_pkicad', 'cert-postsave-command': '/usr/libexec/ipa/certmonger/renew_ca_cert "auditSigningCert cert-pki-ca"', 'ca-profile': 'caSignedLogCert'} 2025-05-07T18:05:41Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:41Z DEBUG start tracking {'TRACK': True, 'CERT_STORAGE': 'NSSDB', 'KEY_STORAGE': 'NSSDB', 'CERT_LOCATION': '/etc/pki/pki-tomcat/alias', 'KEY_LOCATION': '/etc/pki/pki-tomcat/alias', 'CA': dbus.ObjectPath('/org/fedorahosted/certmonger/cas/CA5'), 'CERT_NICKNAME': 'ocspSigningCert cert-pki-ca', 'KEY_NICKNAME': 'ocspSigningCert cert-pki-ca', 'KEY_PIN': '7My^4a)E?PI(B1T%lZk}97X-nIw~[IPgAZy|9yr2G', 'cert-presave-command': '/usr/libexec/ipa/certmonger/stop_pkicad', 'cert-postsave-command': '/usr/libexec/ipa/certmonger/renew_ca_cert "ocspSigningCert cert-pki-ca"', 'ca-profile': 'caOCSPCert'} 2025-05-07T18:05:41Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:41Z DEBUG start tracking {'TRACK': True, 'CERT_STORAGE': 'NSSDB', 'KEY_STORAGE': 'NSSDB', 'CERT_LOCATION': '/etc/pki/pki-tomcat/alias', 'KEY_LOCATION': '/etc/pki/pki-tomcat/alias', 'CA': dbus.ObjectPath('/org/fedorahosted/certmonger/cas/CA5'), 'CERT_NICKNAME': 'subsystemCert cert-pki-ca', 'KEY_NICKNAME': 'subsystemCert cert-pki-ca', 'KEY_PIN': '7My^4a)E?PI(B1T%lZk}97X-nIw~[IPgAZy|9yr2G', 'cert-presave-command': '/usr/libexec/ipa/certmonger/stop_pkicad', 'cert-postsave-command': '/usr/libexec/ipa/certmonger/renew_ca_cert "subsystemCert cert-pki-ca"', 'ca-profile': 'caSubsystemCert'} 2025-05-07T18:05:42Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:42Z DEBUG start tracking {'TRACK': True, 'CERT_STORAGE': 'NSSDB', 'KEY_STORAGE': 'NSSDB', 'CERT_LOCATION': '/etc/pki/pki-tomcat/alias', 'KEY_LOCATION': '/etc/pki/pki-tomcat/alias', 'CA': dbus.ObjectPath('/org/fedorahosted/certmonger/cas/CA5'), 'CERT_NICKNAME': 'caSigningCert cert-pki-ca', 'KEY_NICKNAME': 'caSigningCert cert-pki-ca', 'KEY_PIN': '7My^4a)E?PI(B1T%lZk}97X-nIw~[IPgAZy|9yr2G', 'cert-presave-command': '/usr/libexec/ipa/certmonger/stop_pkicad', 'cert-postsave-command': '/usr/libexec/ipa/certmonger/renew_ca_cert "caSigningCert cert-pki-ca"', 'ca-profile': 'caCACert'} 2025-05-07T18:05:43Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:43Z DEBUG start tracking {'TRACK': True, 'CERT_STORAGE': 'NSSDB', 'KEY_STORAGE': 'NSSDB', 'CERT_LOCATION': '/etc/pki/pki-tomcat/alias', 'KEY_LOCATION': '/etc/pki/pki-tomcat/alias', 'CA': dbus.ObjectPath('/org/fedorahosted/certmonger/cas/CA5'), 'CERT_NICKNAME': 'Server-Cert cert-pki-ca', 'KEY_NICKNAME': 'Server-Cert cert-pki-ca', 'KEY_PIN': '7My^4a)E?PI(B1T%lZk}97X-nIw~[IPgAZy|9yr2G', 'cert-presave-command': '/usr/libexec/ipa/certmonger/stop_pkicad', 'cert-postsave-command': '/usr/libexec/ipa/certmonger/renew_ca_cert "Server-Cert cert-pki-ca"', 'ca-profile': 'caServerCert'} 2025-05-07T18:05:44Z DEBUG step duration: pki-tomcatd configure_renewal 3.91 sec 2025-05-07T18:05:44Z DEBUG [24/33]: Configure HTTP to proxy connections 2025-05-07T18:05:44Z DEBUG step duration: pki-tomcatd http_proxy 0.00 sec 2025-05-07T18:05:44Z DEBUG [25/33]: enabling CA instance 2025-05-07T18:05:44Z DEBUG Starting external process 2025-05-07T18:05:44Z DEBUG args=['/bin/systemctl', 'unmask', 'pki-tomcatd.target'] 2025-05-07T18:05:44Z DEBUG Process finished, return code=0 2025-05-07T18:05:44Z DEBUG stdout= 2025-05-07T18:05:44Z DEBUG stderr= 2025-05-07T18:05:44Z DEBUG Starting external process 2025-05-07T18:05:44Z DEBUG args=['/bin/systemctl', 'disable', 'pki-tomcatd.target'] 2025-05-07T18:05:44Z DEBUG Process finished, return code=0 2025-05-07T18:05:44Z DEBUG stdout= 2025-05-07T18:05:44Z DEBUG stderr= 2025-05-07T18:05:44Z DEBUG step duration: pki-tomcatd __enable_instance 0.74 sec 2025-05-07T18:05:44Z DEBUG [26/33]: importing IPA certificate profiles 2025-05-07T18:05:44Z DEBUG Discovery: no 'CA' service found. 2025-05-07T18:05:44Z DEBUG request GET https://master.ufreeipa.test:443/ca/rest/account/login 2025-05-07T18:05:44Z DEBUG request body '' 2025-05-07T18:05:44Z DEBUG httplib request failed: Traceback (most recent call last): File "/usr/lib/python3.13/site-packages/ipapython/dogtag.py", line 271, in _httplib_request conn.request(method, path, body=request_body, headers=headers) ~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib64/python3.13/http/client.py", line 1338, in request self._send_request(method, url, body, headers, encode_chunked) ~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib64/python3.13/http/client.py", line 1384, in _send_request self.endheaders(body, encode_chunked=encode_chunked) ~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib64/python3.13/http/client.py", line 1333, in endheaders self._send_output(message_body, encode_chunked=encode_chunked) ~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib64/python3.13/http/client.py", line 1093, in _send_output self.send(msg) ~~~~~~~~~^^^^^ File "/usr/lib64/python3.13/http/client.py", line 1037, in send self.connect() ~~~~~~~~~~~~^^ File "/usr/lib64/python3.13/http/client.py", line 1472, in connect super().connect() ~~~~~~~~~~~~~~~^^ File "/usr/lib64/python3.13/http/client.py", line 1003, in connect self.sock = self._create_connection( ~~~~~~~~~~~~~~~~~~~~~~~^ (self.host,self.port), self.timeout, self.source_address) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib64/python3.13/socket.py", line 864, in create_connection raise exceptions[0] File "/usr/lib64/python3.13/socket.py", line 849, in create_connection sock.connect(sa) ~~~~~~~~~~~~^^^^ ConnectionRefusedError: [Errno 111] Connection refused 2025-05-07T18:05:44Z DEBUG Overriding CA port: cannot connect to 'https://master.ufreeipa.test:443/ca/rest/account/login': [Errno 111] Connection refused 2025-05-07T18:05:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:05:45Z DEBUG Trying to find certificate subject base in sysupgrade 2025-05-07T18:05:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:05:45Z DEBUG Found certificate subject base in sysupgrade: O=UFREEIPA.TEST 2025-05-07T18:05:45Z DEBUG Discovery: no 'CA' service found. 2025-05-07T18:05:45Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/login 2025-05-07T18:05:45Z DEBUG request body '' 2025-05-07T18:05:45Z DEBUG response status 200 2025-05-07T18:05:45Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=BB60E879784F7ABE869663BEC1E9A5A2; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2025-05-07T18:05:45Z DEBUG request POST https://master.ufreeipa.test:8443/ca/rest/profiles/raw 2025-05-07T18:05:45Z DEBUG request body 'profileId=caIPAserviceCert\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=UFREEIPA.TEST\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.ufreeipa.test/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\n' 2025-05-07T18:05:45Z DEBUG response status 409 2025-05-07T18:05:45Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2025-05-07T18:05:45Z DEBUG Error migrating 'caIPAserviceCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Unable to create profile: Profile already exists 2025-05-07T18:05:45Z DEBUG request POST https://master.ufreeipa.test:8443/ca/rest/profiles/caIPAserviceCert?action=disable 2025-05-07T18:05:45Z DEBUG request body '' 2025-05-07T18:05:45Z DEBUG response status 204 2025-05-07T18:05:45Z DEBUG response headers Content-Type: application/json Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'' 2025-05-07T18:05:45Z DEBUG request PUT https://master.ufreeipa.test:8443/ca/rest/profiles/caIPAserviceCert/raw 2025-05-07T18:05:45Z DEBUG request body 'profileId=caIPAserviceCert\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=UFREEIPA.TEST\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.ufreeipa.test/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\n' 2025-05-07T18:05:45Z DEBUG response status 200 2025-05-07T18:05:45Z DEBUG response headers Cache-Control: private Content-Type: application/json Content-Length: 7307 Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'#Wed May 07 18:05:45 UTC 2025\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.2.default.params.range=731\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=raCertAuth\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\nvisible=false\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=UFREEIPA.TEST\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.ufreeipa.test/ca/ocsp\n' 2025-05-07T18:05:45Z DEBUG request POST https://master.ufreeipa.test:8443/ca/rest/profiles/caIPAserviceCert?action=enable 2025-05-07T18:05:45Z DEBUG request body '' 2025-05-07T18:05:45Z DEBUG response status 204 2025-05-07T18:05:45Z DEBUG response headers Content-Type: application/json Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'' 2025-05-07T18:05:45Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/logout 2025-05-07T18:05:45Z DEBUG request body '' 2025-05-07T18:05:45Z DEBUG response status 204 2025-05-07T18:05:45Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=6DCE0551E04855BAAAEFA3B60B1384F3; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'' 2025-05-07T18:05:45Z DEBUG Imported profile 'caIPAserviceCert' 2025-05-07T18:05:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:05:45Z DEBUG Trying to find certificate subject base in sysupgrade 2025-05-07T18:05:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:05:45Z DEBUG Found certificate subject base in sysupgrade: O=UFREEIPA.TEST 2025-05-07T18:05:45Z DEBUG Discovery: no 'CA' service found. 2025-05-07T18:05:45Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/login 2025-05-07T18:05:45Z DEBUG request body '' 2025-05-07T18:05:45Z DEBUG response status 200 2025-05-07T18:05:45Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=D429698B01C1240F7641449FA9179C00; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2025-05-07T18:05:45Z DEBUG request POST https://master.ufreeipa.test:8443/ca/rest/profiles/raw 2025-05-07T18:05:45Z DEBUG request body 'profileId=acmeIPAServerCert\nclassId=caEnrollImpl\ndesc=ACME profile for use in IPA deployments\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=SessionAuthentication\nauthz.acl=group="Enterprise ACME Administrators"\nname=IPA ACME Service Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11\npolicyset.serverCertSet.1.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.1.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.1.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.1.constraint.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.1.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.1.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.1.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.1.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.1.default.name=Key Usage Default\npolicyset.serverCertSet.1.default.params.keyUsageCritical=true\npolicyset.serverCertSet.1.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.1.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.1.default.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.1.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.1.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.1.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.1.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.1.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.1.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.2.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.2.constraint.name=No Constraint\npolicyset.serverCertSet.2.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.2.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.2.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.3.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.3.constraint.name=No Constraint\npolicyset.serverCertSet.3.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.3.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.3.default.params.critical=false\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.ufreeipa.test/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.6.default.name=User supplied extension in CSR\npolicyset.serverCertSet.6.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.7.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.7.constraint.name=Validity Constraint\npolicyset.serverCertSet.7.constraint.params.range=90\npolicyset.serverCertSet.7.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.7.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.7.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.7.default.name=Validity Default\npolicyset.serverCertSet.7.default.params.range=90\npolicyset.serverCertSet.7.default.params.startTime=0\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=sanToCNDefaultImpl\npolicyset.serverCertSet.9.default.name=SAN to CN Default\npolicyset.serverCertSet.10.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.10.constraint.name=Key Constraint\npolicyset.serverCertSet.10.constraint.params.keyType=RSA\npolicyset.serverCertSet.10.constraint.params.keyParameters=2048,3072,4096,8192\npolicyset.serverCertSet.10.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.10.default.name=Key Default\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.11.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.11.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.11.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.11.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.11.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.11.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.11.default.params.crlDistPointsPointName_0=http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.11.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.11.default.params.crlDistPointsReasons_0=\n' 2025-05-07T18:05:45Z DEBUG response status 201 2025-05-07T18:05:45Z DEBUG response headers Location: https://master.ufreeipa.test:8443/ca/v1/profiles/raw Content-Type: application/json Content-Length: 6732 Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'#Wed May 07 18:05:45 UTC 2025\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=SessionAuthentication\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.1.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=SAN to CN Default\npolicyset.serverCertSet.6.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.params.crlDistPointsPointType_0=URIName\nauthz.acl=group="Enterprise ACME Administrators"\npolicyset.serverCertSet.11.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.1.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.11.default.name=CRL Distribution Points Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.11.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.3.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.7.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.1.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.1.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.2.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.1.constraint.params.keyUsageCritical=true\nvisible=true\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.default.name=Key Default\ndesc=ACME profile for use in IPA deployments\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.1.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.1.constraint.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.2.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.2.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.6.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.10.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.1.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.11.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.7.default.class_id=validityDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.1.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.10.constraint.params.keyType=RSA\npolicyset.serverCertSet.7.default.params.range=90\npolicyset.serverCertSet.7.default.name=Validity Default\npolicyset.serverCertSet.10.constraint.params.keyParameters=2048,3072,4096,8192\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.1.default.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.7.constraint.params.notAfterCheck=false\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=Validity Constraint\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11\npolicyset.serverCertSet.2.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.1.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.7.constraint.params.range=90\nname=IPA ACME Service Certificate Enrollment\npolicyset.serverCertSet.1.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.3.default.params.critical=false\npolicyset.serverCertSet.11.default.params.crlDistPointsPointName_0=http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.11.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.2.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.6.default.name=User supplied extension in CSR\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.1.default.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.class_id=sanToCNDefaultImpl\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.3.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.7.constraint.class_id=validityConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.1.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.1.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.3.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.default.params.startTime=0\npolicyset.serverCertSet.1.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=Key Constraint\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.ufreeipa.test/ca/ocsp\npolicyset.serverCertSet.6.default.params.userExtOID=2.5.29.17\n' 2025-05-07T18:05:45Z DEBUG Profile 'acmeIPAServerCert' successfully migrated to LDAP 2025-05-07T18:05:45Z DEBUG request POST https://master.ufreeipa.test:8443/ca/rest/profiles/acmeIPAServerCert?action=enable 2025-05-07T18:05:45Z DEBUG request body '' 2025-05-07T18:05:45Z DEBUG response status 204 2025-05-07T18:05:45Z DEBUG response headers Content-Type: application/json Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'' 2025-05-07T18:05:45Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/logout 2025-05-07T18:05:45Z DEBUG request body '' 2025-05-07T18:05:45Z DEBUG response status 204 2025-05-07T18:05:45Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=5B3F7B3470C98837C7457942691A3CA6; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'' 2025-05-07T18:05:45Z DEBUG Imported profile 'acmeIPAServerCert' 2025-05-07T18:05:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:05:45Z DEBUG Trying to find certificate subject base in sysupgrade 2025-05-07T18:05:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:05:45Z DEBUG Found certificate subject base in sysupgrade: O=UFREEIPA.TEST 2025-05-07T18:05:45Z DEBUG Discovery: no 'CA' service found. 2025-05-07T18:05:45Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/login 2025-05-07T18:05:45Z DEBUG request body '' 2025-05-07T18:05:45Z DEBUG response status 200 2025-05-07T18:05:45Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=8A046A6D6240DF69F05EDA46E15B4E85; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Wed, 07 May 2025 18:05:45 GMT 2025-05-07T18:05:45Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2025-05-07T18:05:45Z DEBUG request POST https://master.ufreeipa.test:8443/ca/rest/profiles/raw 2025-05-07T18:05:45Z DEBUG request body 'profileId=KDCs_PKINIT_Certs\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=UFREEIPA.TEST\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.ufreeipa.test/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.2.3.5\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\n' 2025-05-07T18:05:46Z DEBUG response status 201 2025-05-07T18:05:46Z DEBUG response headers Location: https://master.ufreeipa.test:8443/ca/v1/profiles/raw Content-Type: application/json Content-Length: 7273 Date: Wed, 07 May 2025 18:05:46 GMT 2025-05-07T18:05:46Z DEBUG response body (decoded): b'#Wed May 07 18:05:45 UTC 2025\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.2.3.5\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.2.default.params.range=731\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=raCertAuth\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\nvisible=false\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.3.constraint.params.keyParameters=2048,3072,4096\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=UFREEIPA.TEST\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.ufreeipa.test/ca/ocsp\n' 2025-05-07T18:05:46Z DEBUG Profile 'KDCs_PKINIT_Certs' successfully migrated to LDAP 2025-05-07T18:05:46Z DEBUG request POST https://master.ufreeipa.test:8443/ca/rest/profiles/KDCs_PKINIT_Certs?action=enable 2025-05-07T18:05:46Z DEBUG request body '' 2025-05-07T18:05:46Z DEBUG response status 204 2025-05-07T18:05:46Z DEBUG response headers Content-Type: application/json Date: Wed, 07 May 2025 18:05:46 GMT 2025-05-07T18:05:46Z DEBUG response body (decoded): b'' 2025-05-07T18:05:46Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/logout 2025-05-07T18:05:46Z DEBUG request body '' 2025-05-07T18:05:46Z DEBUG response status 204 2025-05-07T18:05:46Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=E5B64DEC43E973E7F6D79B920C8EAB84; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Wed, 07 May 2025 18:05:46 GMT 2025-05-07T18:05:46Z DEBUG response body (decoded): b'' 2025-05-07T18:05:46Z DEBUG Imported profile 'KDCs_PKINIT_Certs' 2025-05-07T18:05:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:46Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:05:46Z DEBUG Trying to find certificate subject base in sysupgrade 2025-05-07T18:05:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:05:46Z DEBUG Found certificate subject base in sysupgrade: O=UFREEIPA.TEST 2025-05-07T18:05:46Z DEBUG Discovery: no 'CA' service found. 2025-05-07T18:05:46Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/login 2025-05-07T18:05:46Z DEBUG request body '' 2025-05-07T18:05:46Z DEBUG response status 200 2025-05-07T18:05:46Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=A27DF299939E96C0DC5740502DB8278E; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Wed, 07 May 2025 18:05:46 GMT 2025-05-07T18:05:46Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2025-05-07T18:05:46Z DEBUG request POST https://master.ufreeipa.test:8443/ca/rest/profiles/raw 2025-05-07T18:05:46Z DEBUG request body 'profileId=IECUserRoles\nclassId=caEnrollImpl\ndesc=Enroll user certificates with IECUserRoles extension via IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=UFREEIPA.TEST\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.ufreeipa.test/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.12.default.name=IECUserRoles Extension Default\npolicyset.serverCertSet.12.default.params.userExtOID=1.2.840.10070.8.1\n' 2025-05-07T18:05:46Z DEBUG response status 201 2025-05-07T18:05:46Z DEBUG response headers Location: https://master.ufreeipa.test:8443/ca/v1/profiles/raw Content-Type: application/json Content-Length: 7347 Date: Wed, 07 May 2025 18:05:46 GMT 2025-05-07T18:05:46Z DEBUG response body (decoded): b'#Wed May 07 18:05:46 UTC 2025\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.2.default.params.range=731\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=raCertAuth\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\nvisible=false\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\ndesc=Enroll user certificates with IECUserRoles extension via IPA-RA agent authentication.\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=UFREEIPA.TEST\npolicyset.serverCertSet.12.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.12.default.params.userExtOID=1.2.840.10070.8.1\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.12.default.name=IECUserRoles Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.ufreeipa.test/ca/ocsp\n' 2025-05-07T18:05:46Z DEBUG Profile 'IECUserRoles' successfully migrated to LDAP 2025-05-07T18:05:46Z DEBUG request POST https://master.ufreeipa.test:8443/ca/rest/profiles/IECUserRoles?action=enable 2025-05-07T18:05:46Z DEBUG request body '' 2025-05-07T18:05:46Z DEBUG response status 204 2025-05-07T18:05:46Z DEBUG response headers Content-Type: application/json Date: Wed, 07 May 2025 18:05:46 GMT 2025-05-07T18:05:46Z DEBUG response body (decoded): b'' 2025-05-07T18:05:46Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/logout 2025-05-07T18:05:46Z DEBUG request body '' 2025-05-07T18:05:46Z DEBUG response status 204 2025-05-07T18:05:46Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=31D0A25C28161A24E2E64C81133611FF; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Wed, 07 May 2025 18:05:46 GMT 2025-05-07T18:05:46Z DEBUG response body (decoded): b'' 2025-05-07T18:05:46Z DEBUG Imported profile 'IECUserRoles' 2025-05-07T18:05:46Z DEBUG step duration: pki-tomcatd import_included_profiles 1.51 sec 2025-05-07T18:05:46Z DEBUG [27/33]: migrating certificate profiles to LDAP 2025-05-07T18:05:46Z DEBUG Profile 'acmeServerCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCserverCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCECserverCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCECsubsystemCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCsubsystemCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCauditSigningCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCcaCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCocspCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCkraTransportCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCkraStorageCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caServerKeygen_UserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caServerKeygen_DirUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECUserCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caUserSMIMEcapCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caDualCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caDirBasedDualCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'AdminCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'ECAdminCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caSignedLogCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTPSCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caRARouterCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caRouterCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caServerCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECServerCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caServerCertWithSCT' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECServerCertWithSCT' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caSubsystemCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECSubsystemCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caOtherCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCACert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCcaCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCrossSignedCACert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caInstallCACert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caRACert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caOCSPCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caStorageCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTransportCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caDirPinUserCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECDirPinUserCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caDirUserCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECDirUserCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caAgentServerCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECAgentServerCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caAgentFileSigning' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCECUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caCMCcaIssuanceProtectionCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caFullCMCUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECFullCMCUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caFullCMCUserSignedCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECFullCMCUserSignedCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caFullCMCSharedTokenCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECFullCMCSharedTokenCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caSimpleCMCUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECSimpleCMCUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTokenDeviceKeyEnrollment' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTokenUserEncryptionKeyEnrollment' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTokenUserSigningKeyEnrollment' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTempTokenDeviceKeyEnrollment' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTempTokenUserEncryptionKeyEnrollment' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTempTokenUserSigningKeyEnrollment' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caAdminCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECAdminCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caInternalAuthServerCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECInternalAuthServerCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caInternalAuthTransportCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caInternalAuthDRMstorageCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caInternalAuthSubsystemCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caECInternalAuthSubsystemCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caInternalAuthOCSPCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caInternalAuthAuditSigningCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'DomainController' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caDualRAuserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caRAagentCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caRAserverCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caUUIDdeviceCert' is already in LDAP and disabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caSSLClientSelfRenewal' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caDirUserRenewal' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caManualRenewal' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTokenMSLoginEnrollment' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTokenUserSigningKeyRenewal' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTokenUserEncryptionKeyRenewal' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTokenUserAuthKeyRenewal' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caJarSigningCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caIPAserviceCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caAuditSigningCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caEncUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caSigningUserCert' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTokenUserDelegateAuthKeyEnrollment' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG Profile 'caTokenUserDelegateSigningKeyEnrollment' is already in LDAP and enabled; skipping 2025-05-07T18:05:46Z DEBUG step duration: pki-tomcatd migrate_profiles_to_ldap 0.03 sec 2025-05-07T18:05:46Z DEBUG [28/33]: adding default CA ACL 2025-05-07T18:05:46Z DEBUG raw: caacl_find(None, version='2.254') 2025-05-07T18:05:46Z DEBUG caacl_find(None, all=False, raw=False, version='2.254', no_members=True, pkey_only=False) 2025-05-07T18:05:46Z DEBUG raw: caacl_add('hosts_services_caIPAserviceCert', hostcategory='all', servicecategory='all', version='2.254') 2025-05-07T18:05:46Z DEBUG caacl_add('hosts_services_caIPAserviceCert', hostcategory='all', servicecategory='all', all=False, raw=False, version='2.254', no_members=False) 2025-05-07T18:05:46Z DEBUG raw: caacl_add_profile('hosts_services_caIPAserviceCert', version='2.254', certprofile=('caIPAserviceCert',)) 2025-05-07T18:05:46Z DEBUG caacl_add_profile('hosts_services_caIPAserviceCert', all=False, raw=False, version='2.254', no_members=False, certprofile=('caIPAserviceCert',)) 2025-05-07T18:05:46Z DEBUG add_entry_to_group: dn=cn=caIPAserviceCert,cn=certprofiles,cn=ca,dc=ufreeipa,dc=test group_dn=ipaUniqueID=e68ed43a-2b6d-11f0-987e-fa163e36f7a6,cn=caacls,cn=ca,dc=ufreeipa,dc=test member_attr=ipamembercertprofile 2025-05-07T18:05:46Z DEBUG step duration: pki-tomcatd ensure_default_caacl 0.45 sec 2025-05-07T18:05:46Z DEBUG [29/33]: adding 'ipa' CA entry 2025-05-07T18:05:46Z DEBUG Discovery: no 'CA' service found. 2025-05-07T18:05:46Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/login 2025-05-07T18:05:46Z DEBUG request body '' 2025-05-07T18:05:46Z DEBUG response status 200 2025-05-07T18:05:46Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=DA66F8EDE4750688A9850BA8E96273FA; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Wed, 07 May 2025 18:05:46 GMT 2025-05-07T18:05:46Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2025-05-07T18:05:46Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/authorities/host-authority 2025-05-07T18:05:46Z DEBUG request body '' 2025-05-07T18:05:47Z DEBUG response status 200 2025-05-07T18:05:47Z DEBUG response headers Cache-Control: private Content-Type: application/json Content-Length: 277 Date: Wed, 07 May 2025 18:05:47 GMT 2025-05-07T18:05:47Z DEBUG response body (decoded): b'{"isHostAuthority":true,"id":"0594229b-6a83-4bd5-ba1e-e34cb20753b5","issuerDN":"CN=Certificate Authority,O=UFREEIPA.TEST","serial":91682445989297502188288508781115781589,"dn":"CN=Certificate Authority,O=UFREEIPA.TEST","enabled":true,"description":"Host authority","ready":true}' 2025-05-07T18:05:47Z DEBUG request GET https://master.ufreeipa.test:8443/ca/rest/account/logout 2025-05-07T18:05:47Z DEBUG request body '' 2025-05-07T18:05:47Z DEBUG response status 204 2025-05-07T18:05:47Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=1FBABE58D225472008E142404EFB17A7; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Wed, 07 May 2025 18:05:47 GMT 2025-05-07T18:05:47Z DEBUG response body (decoded): b'' 2025-05-07T18:05:47Z DEBUG step duration: pki-tomcatd ensure_ipa_authority_entry 0.27 sec 2025-05-07T18:05:47Z DEBUG [30/33]: Recording random serial number state 2025-05-07T18:05:47Z DEBUG update_entry modlist [(2, 'ipaCaRandomSerialNumberVersion', [b'3'])] 2025-05-07T18:05:47Z DEBUG step duration: pki-tomcatd __store_random_serial_number_state 0.02 sec 2025-05-07T18:05:47Z DEBUG [31/33]: Recording HSM configuration state 2025-05-07T18:05:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:05:47Z DEBUG step duration: pki-tomcatd __store_hsm_configuration_state 0.00 sec 2025-05-07T18:05:47Z DEBUG [32/33]: configuring certmonger renewal for lightweight CAs 2025-05-07T18:05:47Z DEBUG step duration: pki-tomcatd add_lightweight_ca_tracking_requests 0.01 sec 2025-05-07T18:05:47Z DEBUG [33/33]: deploying ACME service 2025-05-07T18:05:47Z DEBUG Deploying ACME 2025-05-07T18:05:47Z DEBUG Starting external process 2025-05-07T18:05:47Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/pki/acme/database/ds/schema.ldif', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:05:47Z DEBUG Process finished, return code=0 2025-05-07T18:05:47Z DEBUG stdout=add attributeTypes: ( acmeCreated-oid NAME 'acmeCreated' SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 EQUALITY generalizedTimeMatch ORDERING generalizedTimeOrderingMatch SINGLE-VALUE ) ( acmeExpires-oid NAME 'acmeExpires' SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 EQUALITY generalizedTimeMatch ORDERING generalizedTimeOrderingMatch SINGLE-VALUE ) ( acmeValidatedAt-oid NAME 'acmeValidatedAt' SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 EQUALITY generalizedTimeMatch ORDERING generalizedTimeOrderingMatch SINGLE-VALUE ) ( acmeStatus-oid NAME 'acmeStatus' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 EQUALITY caseIgnoreMatch SINGLE-VALUE ) ( acmeError-oid NAME 'acmeError' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE ) ( acmeNonceId-oid NAME 'acmeNonceId' SUP name SINGLE-VALUE ) ( acmeAccountId-oid NAME 'acmeAccountId' SUP name SINGLE-VALUE ) ( acmeAccountContact-oid NAME 'acmeAccountContact' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch ) ( acmeAccountKey-oid NAME 'acmeAccountKey' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE ) ( acmeOrderId-oid NAME 'acmeOrderId' SUP name SINGLE-VALUE ) ( acmeIdentifier-oid NAME 'acmeIdentifier' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 EQUALITY caseIgnoreMatch ) ( acmeAuthorizationId-oid NAME 'acmeAuthorizationId' SUP name ) ( acmeAuthorizationWildcard-oid NAME 'acmeAuthorizationWildcard' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 EQUALITY booleanMatch SINGLE-VALUE ) ( acmeChallengeId-oid NAME 'acmeChallengeId' SUP name SINGLE-VALUE ) ( acmeToken-oid NAME 'acmeToken' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) ( acmeCertificateId-oid NAME 'acmeCertificateId' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 EQUALITY caseExactMatch SINGLE-VALUE ) ( acmeEnabled-oid NAME 'acmeEnabled' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 EQUALITY booleanMatch SINGLE-VALUE ) add objectClasses: ( acmeNonce-oid NAME 'acmeNonce' STRUCTURAL MUST ( acmeNonceId $ acmeCreated $ acmeExpires ) ) ( acmeAccount-oid NAME 'acmeAccount' STRUCTURAL MUST ( acmeAccountId $ acmeCreated $ acmeAccountKey $ acmeStatus ) MAY acmeAccountContact ) ( acmeOrder-oid NAME 'acmeOrder' STRUCTURAL MUST ( acmeOrderId $ acmeAccountId $ acmeCreated $ acmeStatus $ acmeIdentifier $ acmeAuthorizationId ) MAY ( acmeError $ acmeCertificateId $ acmeExpires ) ) ( acmeAuthorization-oid NAME 'acmeAuthorization' STRUCTURAL MUST ( acmeAuthorizationId $ acmeAccountId $ acmeCreated $ acmeIdentifier $ acmeAuthorizationWildcard $ acmeStatus ) MAY acmeExpires ) ( acmeChallenge-oid NAME 'acmeChallenge' ABSTRACT MUST ( acmeChallengeId $ acmeAccountId $ acmeAuthorizationId $ acmeStatus ) MAY ( acmeValidatedAt $ acmeError ) ) ( acmeChallengeDns01-oid NAME 'acmeChallengeDns01' SUP acmeChallenge STRUCTURAL MUST acmeToken ) ( acmeChallengeHttp01-oid NAME 'acmeChallengeHttp01' SUP acmeChallenge STRUCTURAL MUST acmeToken ) ( acmeCertificate-oid NAME 'acmeCertificate' STRUCTURAL MUST ( acmeCertificateId $ acmeCreated $ userCertificate ) MAY acmeExpires ) modifying entry "cn=schema" modify complete 2025-05-07T18:05:47Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:05:47Z DEBUG update_entry modlist [(0, 'resourceACLS', [b'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations'])] 2025-05-07T18:05:47Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Enterprise ACME Administrators,ou=groups,o=ipaca member_attr=uniqueMember 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['pki-server', 'acme-create'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['pki-server', 'acme-deploy'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG step duration: pki-tomcatd setup_acme 1.58 sec 2025-05-07T18:05:48Z DEBUG Done configuring certificate server (pki-tomcatd). 2025-05-07T18:05:48Z DEBUG service duration: pki-tomcatd 190.74 sec 2025-05-07T18:05:48Z DEBUG Removing /root/.dogtag/pki-tomcat/ca 2025-05-07T18:05:48Z DEBUG Configuring directory server (dirsrv) 2025-05-07T18:05:48Z DEBUG [1/3]: configuring TLS for DS instance 2025-05-07T18:05:48Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-UFREEIPA-TEST/', '-L', '-n', 'UFREEIPA.TEST IPA CA', '-a', '-f', '/etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=255 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr=certutil: Could not find cert: UFREEIPA.TEST IPA CA : PR_FILE_NOT_FOUND_ERROR: File not found 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-UFREEIPA-TEST/', '-N', '-f', '/etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt', '-@', '/etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-UFREEIPA-TEST/'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-UFREEIPA-TEST/cert9.db'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-UFREEIPA-TEST/key4.db'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-UFREEIPA-TEST/pkcs11.txt'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt'] 2025-05-07T18:05:48Z DEBUG Process finished, return code=0 2025-05-07T18:05:48Z DEBUG stdout= 2025-05-07T18:05:48Z DEBUG stderr= 2025-05-07T18:05:48Z DEBUG Starting external process 2025-05-07T18:05:48Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-UFREEIPA-TEST/', '-A', '-n', 'UFREEIPA.TEST IPA CA', '-t', 'CT,C,C', '-a', '-f', '/etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt'] 2025-05-07T18:05:49Z DEBUG Process finished, return code=0 2025-05-07T18:05:49Z DEBUG stdout= 2025-05-07T18:05:49Z DEBUG stderr= 2025-05-07T18:05:49Z DEBUG certmonger request is in state 'NEWLY_ADDED_READING_KEYINFO' 2025-05-07T18:05:50Z DEBUG certmonger request is in state 'GENERATING_KEY_PAIR' 2025-05-07T18:05:50Z DEBUG certmonger request is in state 'READING_CERT' 2025-05-07T18:05:51Z DEBUG certmonger request is in state 'POST_SAVED_CERT' 2025-05-07T18:05:53Z DEBUG certmonger request is in state 'MONITORING' 2025-05-07T18:05:53Z DEBUG Cert request 20250507180549 was successful 2025-05-07T18:05:53Z DEBUG Destroyed connection context.ldap2_139937138938208 2025-05-07T18:05:53Z DEBUG Created connection context.ldap2_139937138938208 2025-05-07T18:05:53Z DEBUG Starting external process 2025-05-07T18:05:53Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-UFREEIPA-TEST/', '-L', '-n', 'Server-Cert', '-a', '-f', '/etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt'] 2025-05-07T18:05:53Z DEBUG Process finished, return code=0 2025-05-07T18:05:53Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIFTzCCA7egAwIBAgIRANgdYG075ySqEq5QR4e2aEUwDQYJKoZIhvcNAQELBQAw ODEWMBQGA1UECgwNVUZSRUVJUEEuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUg QXV0aG9yaXR5MB4XDTI1MDUwNzE4MDU1MFoXDTI3MDUwODE4MDU1MFowNzEWMBQG A1UECgwNVUZSRUVJUEEuVEVTVDEdMBsGA1UEAwwUbWFzdGVyLnVmcmVlaXBhLnRl c3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCz9M3AYJ4E5kvQEU08 dBhZVXHPlgSlbnaQY9ywE6MIn1ZzsQ72FHKD98wMRJibLhy4txvJ1jcXWlg5gETO oKh5gWFcDfEONR2nW2egVk9+ESgvXtteCVL6TrlS/BxZ03fLZ3crNDYLAHxaySN4 GtwzSJ7fQXSD5h8oXc9V1JFvQo/P92fvNKwI4GtSVb+spjKECbgvWfL/U7e+DsWV njNevy4zYspWWWOxXCoHzYD4SyTo8jLRUOFqbEGK2vWnfjIa5LD9wXoavLPBbHud AYdW1ADkmCI9WwAom6BuM9aallcu571We8HugV7rR4HP3LeaIU8Rm0hW9yoqE5Wq JvIxAgMBAAGjggHTMIIBzzAfBgNVHSMEGDAWgBQG+KLSlDPeRxDFeHXQQ0yJR6mN bDA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAGGI2h0dHA6Ly9pcGEtY2EudWZy ZWVpcGEudGVzdC9jYS9vY3NwMA4GA1UdDwEB/wQEAwIE8DAdBgNVHSUEFjAUBggr BgEFBQcDAQYIKwYBBQUHAwIweAYDVR0fBHEwbzBtoDWgM4YxaHR0cDovL2lwYS1j YS51ZnJlZWlwYS50ZXN0L2lwYS9jcmwvTWFzdGVyQ1JMLmJpbqI0pDIwMDEOMAwG A1UECgwFaXBhY2ExHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAdBgNV HQ4EFgQU4PEBVgzYQXh906W+UR2ITbByvHgwgaIGA1UdEQSBmjCBl4IUbWFzdGVy LnVmcmVlaXBhLnRlc3SgNwYKKwYBBAGCNxQCA6ApDCdsZGFwL21hc3Rlci51ZnJl ZWlwYS50ZXN0QFVGUkVFSVBBLlRFU1SgRgYGKwYBBQICoDwwOqAPGw1VRlJFRUlQ QS5URVNUoScwJaADAgEBoR4wHBsEbGRhcBsUbWFzdGVyLnVmcmVlaXBhLnRlc3Qw DQYJKoZIhvcNAQELBQADggGBAC3EW8tIx0b6WEBH1v59bKIq0sj8xGNoHd7sSSP+ vkuG81LKmB4wVhdcInD1GqKlo3emQ6si/wAM5cD9NF3IJjl3bzyiU/P0jXi0Wwg4 GyKGss/5KqPkiHhnYZAoYZGpStQRg9gRVHssLK7jhrTcDQuPnSOdAKtW650kLZSA euP00MjB+tEEZwkfVe7lqEyXwPQfvqdIZUfNLQdlWRlKSFt4AQrzC1g+vJ4tzZi2 cNVF9j4DZZ66Zybuc9a0ttrE+/oE30cXhSVQkqOCwt3WGKFI7iq0RYcP8nXP/kXT IERZWC739R2MqWmqgPZrbo85Vc6tHpZ8n0ojyTxs1y9wGGs2vbjG4qQwEex2CtEb epLzN2hfp/fOeqjgTINsFNaQlazrbCTQOkP56fZarnpn9A04QTb+EEiDwia7CIV/ qmFcvusvNiH3EZJWBvzGXhu5NWTnBZH8WwFwgiWZ4peWRQ+cAefvRp39yvQg24wn 6tEN/UK4JgVmtvTusuRLHt5tqQ== -----END CERTIFICATE----- 2025-05-07T18:05:53Z DEBUG stderr= 2025-05-07T18:05:53Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:05:53Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:05:53Z DEBUG update_entry modlist [(2, 'userCertificate', [b'0\x82\x05O0\x82\x03\xb7\xa0\x03\x02\x01\x02\x02\x11\x00\xd8\x1d`m;\xe7$\xaa\x12\xaePG\x87\xb6hE0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x0b\x05\x00081\x160\x14\x06\x03U\x04\n\x0c\rUFREEIPA.TEST1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x1e\x17\r250507180550Z\x17\r270508180550Z071\x160\x14\x06\x03U\x04\n\x0c\rUFREEIPA.TEST1\x1d0\x1b\x06\x03U\x04\x03\x0c\x14master.ufreeipa.test0\x82\x01"0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x82\x01\x0f\x000\x82\x01\n\x02\x82\x01\x01\x00\xb3\xf4\xcd\xc0`\x9e\x04\xe6K\xd0\x11M\xbc\x9e-\xcd\x98\xb6p\xd5E\xf6>\x03e\x9e\xbag&\xees\xd6\xb4\xb6\xda\xc4\xfb\xfa\x04\xdfG\x17\x85%P\x92\xa3\x82\xc2\xdd\xd6\x18\xa1H\xee*\xb4E\x87\x0f\xf2u\xcf\xfeE\xd3 DYX.\xf7\xf5\x1d\x8c\xa9i\xaa\x80\xf6kn\x8f9U\xce\xad\x1e\x96|\x9fJ#\xc9 2025-05-07T18:05:57Z DEBUG Retrieving keytab 2025-05-07T18:05:57Z DEBUG Starting external process 2025-05-07T18:05:57Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/pki/pki-tomcat/dogtag.keytab dogtag/master.ufreeipa.test@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:05:58Z DEBUG Process finished, return code=0 2025-05-07T18:05:58Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Entry for principal dogtag/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. 2025-05-07T18:05:58Z DEBUG stderr= 2025-05-07T18:05:58Z DEBUG Creating Custodia keys 2025-05-07T18:05:59Z DEBUG Configuring key retriever 2025-05-07T18:05:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:05:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:05:59Z DEBUG Destroyed connection context.ldap2_139937138938208 2025-05-07T18:05:59Z DEBUG Starting external process 2025-05-07T18:05:59Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:06:00Z DEBUG Process finished, return code=0 2025-05-07T18:06:00Z DEBUG stdout= 2025-05-07T18:06:00Z DEBUG stderr= 2025-05-07T18:06:00Z DEBUG Restart of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:06:00Z DEBUG Created connection context.ldap2_139937138938208 2025-05-07T18:06:00Z DEBUG Starting external process 2025-05-07T18:06:00Z DEBUG args=['/bin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2025-05-07T18:06:09Z DEBUG Process finished, return code=0 2025-05-07T18:06:09Z DEBUG stdout= 2025-05-07T18:06:09Z DEBUG stderr= 2025-05-07T18:06:09Z DEBUG Starting external process 2025-05-07T18:06:09Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2025-05-07T18:06:09Z DEBUG Process finished, return code=0 2025-05-07T18:06:09Z DEBUG stdout=active 2025-05-07T18:06:09Z DEBUG stderr= 2025-05-07T18:06:09Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 90 2025-05-07T18:06:09Z DEBUG waiting for port: 8080 2025-05-07T18:06:09Z DEBUG SUCCESS: port: 8080 2025-05-07T18:06:09Z DEBUG waiting for port: 8443 2025-05-07T18:06:09Z DEBUG SUCCESS: port: 8443 2025-05-07T18:06:09Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2025-05-07T18:06:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:09Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:06:09Z DEBUG Configuring ipa-otpd 2025-05-07T18:06:09Z DEBUG [1/2]: starting ipa-otpd 2025-05-07T18:06:09Z DEBUG Starting external process 2025-05-07T18:06:09Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-otpd.socket'] 2025-05-07T18:06:09Z DEBUG Process finished, return code=3 2025-05-07T18:06:09Z DEBUG stdout=inactive 2025-05-07T18:06:09Z DEBUG stderr= 2025-05-07T18:06:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:09Z DEBUG Starting external process 2025-05-07T18:06:09Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-otpd.socket'] 2025-05-07T18:06:09Z DEBUG Process finished, return code=0 2025-05-07T18:06:09Z DEBUG stdout= 2025-05-07T18:06:09Z DEBUG stderr= 2025-05-07T18:06:09Z DEBUG Starting external process 2025-05-07T18:06:09Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-otpd.socket'] 2025-05-07T18:06:09Z DEBUG Process finished, return code=0 2025-05-07T18:06:09Z DEBUG stdout=active 2025-05-07T18:06:09Z DEBUG stderr= 2025-05-07T18:06:09Z DEBUG Restart of ipa-otpd.socket complete 2025-05-07T18:06:09Z DEBUG step duration: ipa-otpd __start 0.03 sec 2025-05-07T18:06:09Z DEBUG [2/2]: configuring ipa-otpd to start on boot 2025-05-07T18:06:09Z DEBUG Starting external process 2025-05-07T18:06:09Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ipa-otpd.socket'] 2025-05-07T18:06:09Z DEBUG Process finished, return code=1 2025-05-07T18:06:09Z DEBUG stdout=disabled 2025-05-07T18:06:09Z DEBUG stderr= 2025-05-07T18:06:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:09Z DEBUG Starting external process 2025-05-07T18:06:09Z DEBUG args=['/bin/systemctl', 'unmask', 'ipa-otpd.socket'] 2025-05-07T18:06:10Z DEBUG Process finished, return code=0 2025-05-07T18:06:10Z DEBUG stdout= 2025-05-07T18:06:10Z DEBUG stderr= 2025-05-07T18:06:10Z DEBUG Starting external process 2025-05-07T18:06:10Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-otpd.socket'] 2025-05-07T18:06:10Z DEBUG Process finished, return code=0 2025-05-07T18:06:10Z DEBUG stdout= 2025-05-07T18:06:10Z DEBUG stderr= 2025-05-07T18:06:10Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:06:10Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:06:10Z DEBUG step duration: ipa-otpd __enable 0.85 sec 2025-05-07T18:06:10Z DEBUG Done configuring ipa-otpd. 2025-05-07T18:06:10Z DEBUG service duration: ipa-otpd 0.89 sec 2025-05-07T18:06:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:10Z DEBUG Configuring the web interface (httpd) 2025-05-07T18:06:10Z DEBUG [1/21]: stopping httpd 2025-05-07T18:06:10Z DEBUG Starting external process 2025-05-07T18:06:10Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2025-05-07T18:06:10Z DEBUG Process finished, return code=3 2025-05-07T18:06:10Z DEBUG stdout=inactive 2025-05-07T18:06:10Z DEBUG stderr= 2025-05-07T18:06:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:10Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:10Z DEBUG Starting external process 2025-05-07T18:06:10Z DEBUG args=['/bin/systemctl', 'stop', 'httpd.service'] 2025-05-07T18:06:10Z DEBUG Process finished, return code=0 2025-05-07T18:06:10Z DEBUG stdout= 2025-05-07T18:06:10Z DEBUG stderr= 2025-05-07T18:06:10Z DEBUG Stop of httpd.service complete 2025-05-07T18:06:10Z DEBUG step duration: httpd __stop 0.05 sec 2025-05-07T18:06:10Z DEBUG [2/21]: backing up ssl.conf 2025-05-07T18:06:10Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ssl.conf' 2025-05-07T18:06:10Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:06:10Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ssl.conf' 2025-05-07T18:06:10Z DEBUG -> Not backing up - already have a copy of '/etc/httpd/conf.d/ssl.conf' 2025-05-07T18:06:10Z DEBUG step duration: httpd backup_ssl_conf 0.00 sec 2025-05-07T18:06:10Z DEBUG [3/21]: configuring mod_ssl certificate paths 2025-05-07T18:06:10Z DEBUG step duration: httpd configure_mod_ssl_certs 0.00 sec 2025-05-07T18:06:10Z DEBUG [4/21]: setting mod_ssl protocol list 2025-05-07T18:06:10Z DEBUG step duration: httpd set_mod_ssl_protocol 0.00 sec 2025-05-07T18:06:10Z DEBUG [5/21]: configuring mod_ssl log directory 2025-05-07T18:06:10Z DEBUG step duration: httpd set_mod_ssl_logdir 0.00 sec 2025-05-07T18:06:10Z DEBUG [6/21]: disabling mod_ssl OCSP 2025-05-07T18:06:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:10Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:10Z DEBUG step duration: httpd disable_mod_ssl_ocsp 0.01 sec 2025-05-07T18:06:10Z DEBUG [7/21]: adding URL rewriting rules 2025-05-07T18:06:10Z DEBUG step duration: httpd __add_include 0.00 sec 2025-05-07T18:06:10Z DEBUG [8/21]: configuring httpd 2025-05-07T18:06:10Z DEBUG Starting external process 2025-05-07T18:06:10Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:06:10Z DEBUG Process finished, return code=0 2025-05-07T18:06:10Z DEBUG stdout= 2025-05-07T18:06:10Z DEBUG stderr= 2025-05-07T18:06:10Z DEBUG Starting external process 2025-05-07T18:06:10Z DEBUG args=['/sbin/restorecon', '/etc/systemd/system/httpd.service.d/ipa.conf'] 2025-05-07T18:06:10Z DEBUG Process finished, return code=0 2025-05-07T18:06:10Z DEBUG stdout= 2025-05-07T18:06:10Z DEBUG stderr= 2025-05-07T18:06:10Z DEBUG Starting external process 2025-05-07T18:06:10Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout= 2025-05-07T18:06:11Z DEBUG stderr= 2025-05-07T18:06:11Z DEBUG Starting external process 2025-05-07T18:06:11Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout= 2025-05-07T18:06:11Z DEBUG stderr= 2025-05-07T18:06:11Z DEBUG Starting external process 2025-05-07T18:06:11Z DEBUG args=['/sbin/restorecon', '/etc/httpd/conf.modules.d/02-ipa-wsgi.conf'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout= 2025-05-07T18:06:11Z DEBUG stderr= 2025-05-07T18:06:11Z DEBUG Starting external process 2025-05-07T18:06:11Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout= 2025-05-07T18:06:11Z DEBUG stderr= 2025-05-07T18:06:11Z DEBUG Starting external process 2025-05-07T18:06:11Z DEBUG args=['/sbin/restorecon', '/etc/httpd/alias'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout= 2025-05-07T18:06:11Z DEBUG stderr= 2025-05-07T18:06:11Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ipa.conf' 2025-05-07T18:06:11Z DEBUG -> Not backing up - '/etc/httpd/conf.d/ipa.conf' doesn't exist 2025-05-07T18:06:11Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ipa-rewrite.conf' 2025-05-07T18:06:11Z DEBUG -> Not backing up - '/etc/httpd/conf.d/ipa-rewrite.conf' doesn't exist 2025-05-07T18:06:11Z DEBUG step duration: httpd __configure_http 0.35 sec 2025-05-07T18:06:11Z DEBUG [9/21]: setting up httpd keytab 2025-05-07T18:06:11Z DEBUG raw: service_add('HTTP/master.ufreeipa.test@UFREEIPA.TEST', force=True, version='2.254') 2025-05-07T18:06:11Z DEBUG service_add(ipapython.kerberos.Principal('HTTP/master.ufreeipa.test@UFREEIPA.TEST'), force=True, skip_host_check=False, all=False, raw=False, version='2.254', no_members=False) 2025-05-07T18:06:11Z DEBUG raw: host_show('master.ufreeipa.test', version='2.254') 2025-05-07T18:06:11Z DEBUG host_show('master.ufreeipa.test', rights=False, all=False, raw=False, version='2.254', no_members=False) 2025-05-07T18:06:11Z DEBUG Backing up system configuration file '/var/lib/ipa/gssproxy/http.keytab' 2025-05-07T18:06:11Z DEBUG -> Not backing up - '/var/lib/ipa/gssproxy/http.keytab' doesn't exist 2025-05-07T18:06:11Z DEBUG Starting external process 2025-05-07T18:06:11Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/var/lib/ipa/gssproxy/http.keytab', '-p', 'HTTP/master.ufreeipa.test@UFREEIPA.TEST', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout= 2025-05-07T18:06:11Z DEBUG stderr=Keytab successfully retrieved and stored in: /var/lib/ipa/gssproxy/http.keytab 2025-05-07T18:06:11Z DEBUG step duration: httpd request_service_keytab 0.44 sec 2025-05-07T18:06:11Z DEBUG [10/21]: configuring Gssproxy 2025-05-07T18:06:11Z DEBUG Starting external process 2025-05-07T18:06:11Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout= 2025-05-07T18:06:11Z DEBUG stderr= 2025-05-07T18:06:11Z DEBUG Starting external process 2025-05-07T18:06:11Z DEBUG args=['/sbin/restorecon', '/etc/gssproxy/10-ipa.conf'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout= 2025-05-07T18:06:11Z DEBUG stderr= 2025-05-07T18:06:11Z DEBUG Starting external process 2025-05-07T18:06:11Z DEBUG args=['/bin/systemctl', 'restart', 'gssproxy.service'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout= 2025-05-07T18:06:11Z DEBUG stderr= 2025-05-07T18:06:11Z DEBUG Starting external process 2025-05-07T18:06:11Z DEBUG args=['/bin/systemctl', 'is-active', 'gssproxy.service'] 2025-05-07T18:06:11Z DEBUG Process finished, return code=0 2025-05-07T18:06:11Z DEBUG stdout=active 2025-05-07T18:06:11Z DEBUG stderr= 2025-05-07T18:06:11Z DEBUG Restart of gssproxy.service complete 2025-05-07T18:06:11Z DEBUG step duration: httpd configure_gssproxy 0.07 sec 2025-05-07T18:06:11Z DEBUG [11/21]: setting up ssl 2025-05-07T18:06:11Z DEBUG certmonger request is in state 'GENERATING_KEY_PAIR' 2025-05-07T18:06:12Z DEBUG certmonger request is in state 'POST_SAVED_CERT' 2025-05-07T18:06:12Z DEBUG certmonger request is in state 'MONITORING' 2025-05-07T18:06:12Z DEBUG Cert request 20250507180611 was successful 2025-05-07T18:06:12Z DEBUG update_entry modlist [(2, 'userCertificate', [b'0\x82\x05d0\x82\x03\xcc\xa0\x03\x02\x01\x02\x02\x10,U\x04Bl\xa1\x08\x17\x87Z\xa3,)\xd6\x05\xbb0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x0b\x05\x00081\x160\x14\x06\x03U\x04\n\x0c\rUFREEIPA.TEST1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x1e\x17\r250507180612Z\x17\r270508180612Z071\x160\x14\x06\x03U\x04\n\x0c\rUFREEIPA.TEST1\x1d0\x1b\x06\x03U\x04\x03\x0c\x14master.ufreeipa.test0\x82\x01"0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x82\x01\x0f\x000\x82\x01\n\x02\x82\x01\x01\x00\xc2\xe6St\xb9F\xff\xa7BS.\xf2\xdfks\xa4]\xac\xecY262\xa5\xe0\xac\x18\x0c)x\x8c\xfe\x81\x92\xbe\xda\x1a\x0eW\x03I\xaa\xeb\x8a\x81\xe3\x1eUb\xa9\xd9\xbez\xc2\xfeL\xee--\x98D\xa7P\xa8rn\x83pIJr\xe0\x81\x19\xcbH\x03\x83\x89x}\x07$\x86P\xca\xcc\xe0\xcdr;\xdb\xa3"\x89_W\x96\xa3+\xea\x86\xa0\xf3}\xe7\x90a\xd3k\xcb($\xab\xd4J\xb9\xdb\xcf\x02\xec\xf9\xcc\\\xfdA\x0c\x1fT\xf2T\x91\xa7;\xea\xc7>P\xd1h\xff\xd0\xfe\x1a=u7R\xbbk\xd5\xd7\xbeN\xa74O-\xf5f\xd7h\xa4\xfe\xfd\xd5\x92%{\x1b\x80\xa8\xac2\xac\x11*l\xc8MX&\xdd,\xeb0\x13\xcb\x99\xe4S\xe6\xf7c\x1aZ\xa5\x14\x17n\xf0S\x92\xab(g\x89+V{\x97\xa3\xf6\x1cL\xf1V\xb2\xfb\x1ed]r\xfd\xb74U\x1at\xa5uW+l\x88@1\xeb&C k\xea\xd5HMH\x1a\xcf\xab/D\xd30\xf5\xc9\x02\x03\x01\x00\x01\xa3\x82\x01\xe90\x82\x01\xe50\x1f\x06\x03U\x1d#\x04\x180\x16\x80\x14\x06\xf8\xa2\xd2\x943\xdeG\x10\xc5xu\xd0CL\x89G\xa9\x8dl0?\x06\x08+\x06\x01\x05\x05\x07\x01\x01\x043010/\x06\x08+\x06\x01\x05\x05\x070\x01\x86#http://ipa-ca.ufreeipa.test/ca/ocsp0\x0e\x06\x03U\x1d\x0f\x01\x01\xff\x04\x04\x03\x02\x04\xf00\x1d\x06\x03U\x1d%\x04\x160\x14\x06\x08+\x06\x01\x05\x05\x07\x03\x01\x06\x08+\x06\x01\x05\x05\x07\x03\x020x\x06\x03U\x1d\x1f\x04q0o0m\xa05\xa03\x861http://ipa-ca.ufreeipa.test/ipa/crl/MasterCRL.bin\xa24\xa42001\x0e0\x0c\x06\x03U\x04\n\x0c\x05ipaca1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x1d\x06\x03U\x1d\x0e\x04\x16\x04\x14"LpM\x8f\x93<\x02\xc6\xf6\xab\xbea\xf7\xfc\x9d\xf3\x9d\xaeJ0\x81\xb8\x06\x03U\x1d\x11\x04\x81\xb00\x81\xad\x82\x14master.ufreeipa.test\x82\x14ipa-ca.ufreeipa.test\xa07\x06\n+\x06\x01\x04\x01\x827\x14\x02\x03\xa0)\x0c\'HTTP/master.ufreeipa.test@UFREEIPA.TEST\xa0F\x06\x06+\x06\x01\x05\x02\x02\xa0<0:\xa0\x0f\x1b\rUFREEIPA.TEST\xa1\'0%\xa0\x03\x02\x01\x01\xa1\x1e0\x1c\x1b\x04HTTP\x1b\x14master.ufreeipa.test0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x0b\x05\x00\x03\x82\x01\x81\x00\xa5\x8cL\x16D\xa1=\xb4E\xbd3\\\x0f\xf6\x9b\x9c,\x1c\xe5\xbb<\x13\xdd^\xce\x8b\x10Q\x07S\xe5s\xe5\x03\x10\x92\tZ\x82\x88\x08/\xebE\xc5\xbcL\xd3h\x0fd4\xe1\xd2\xa9\xe7\xb1\xc5\xd7\x7f\x17\xa6\xa4\xf5^\xc4\xab\t\xf9wA\x8d\xb7\x89\x13K7\xbc\xe5\xe8\x98\xe7\xd7%<\xabO\xa2mz\x9b^@*^w2\xc4\xc7\x99\x1cT\xd0wj\xf7\xb1\x08\xceB\xb3\x00w|\x04\xc5\xe3\xc6\xb74\xc8\xe5ao\xa3*\xf2\xcdLEJ\x1d%D\xd3\xb00\n\xf6Hg\x8b\xa4\x10\xe49\xfb\x9c\xc7\xd9\xc5+S\x83\xa9pM\xda\xbd\x96\xd4\xe7\xed\xce\x8ej\x9e\xb7\xfaJ\xf6 \x98\xe8\xc1\x93\xec\xda\x1e\\\xc9\x1d\xb8%\x90n\xa8E\xa3\x10\'\xe0\xa4#h\x17\xf2\x000\x7f\xf1EM\xee]\x02\xd3\xd09\xc5\x8c\xc2\x98\x9e\xef\x0c}\xe7\xa3\xe0\xe5\xce4\x0f\x92G9N\xa2\xd6\xf8~\xeah\xc0J\xa3E\xdc\xd5\xc7\x8c\x05w6\xcf\xbe=2\xe6\xa4\xafZ\x8c\x11\x05\x17\x1by\xb1\x1b[\xc2\x88[$\xc2\xd0\x9b\x18l\xdd\xa4\x99\ny\x9e\xf7_\x10\xac:=&|\x1e\xb4\xc0\x0b\x97t\x8f\x9b\xd8\xcd\x1c\x9d\x033\x84\x88\xa6\x95YZ\r9\xa6<\xe0OQ\xab>\xc3<\xdd\xbd\xabGO\xa6\x97\x1a\x96X\x13\xd6N\x06\x8c\x173\x1e\xc0^>\xa07\xbe\xcfi\xf5\x03h_\x06\x92\xb8*\x91\x17\xdck\xf9\x8a\t\xa9=P\xb6\x8d\xf9x\xfaL\xc5\x17\xa5\xbf;\xa0\x9f\xc4\x8a\xe9;\xec*W\xbf\x1f\xfb\xec'])] 2025-05-07T18:06:12Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:12Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:12Z DEBUG step duration: httpd __setup_ssl 1.33 sec 2025-05-07T18:06:12Z DEBUG [12/21]: configure certmonger for renewals 2025-05-07T18:06:12Z DEBUG Starting external process 2025-05-07T18:06:12Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2025-05-07T18:06:13Z DEBUG Process finished, return code=0 2025-05-07T18:06:13Z DEBUG stdout=active 2025-05-07T18:06:13Z DEBUG stderr= 2025-05-07T18:06:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:13Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:13Z DEBUG step duration: httpd configure_certmonger_renewal_guard 0.74 sec 2025-05-07T18:06:13Z DEBUG [13/21]: publish CA cert 2025-05-07T18:06:13Z DEBUG step duration: httpd __publish_ca_cert 0.01 sec 2025-05-07T18:06:13Z DEBUG [14/21]: clean up any existing httpd ccaches 2025-05-07T18:06:13Z DEBUG Starting external process 2025-05-07T18:06:13Z DEBUG args=['/bin/systemd-tmpfiles', '--create', '--prefix', '/run/ipa/ccaches'] 2025-05-07T18:06:13Z DEBUG Process finished, return code=0 2025-05-07T18:06:13Z DEBUG stdout= 2025-05-07T18:06:13Z DEBUG stderr= 2025-05-07T18:06:13Z DEBUG step duration: httpd remove_httpd_ccaches 0.07 sec 2025-05-07T18:06:13Z DEBUG [15/21]: enable ccache sweep 2025-05-07T18:06:13Z DEBUG Starting external process 2025-05-07T18:06:13Z DEBUG args=['/bin/systemctl', 'enable', 'ipa-ccache-sweep.timer'] 2025-05-07T18:06:14Z DEBUG Process finished, return code=0 2025-05-07T18:06:14Z DEBUG stdout= 2025-05-07T18:06:14Z DEBUG stderr=Created symlink '/etc/systemd/system/timers.target.wants/ipa-ccache-sweep.timer' → '/usr/lib/systemd/system/ipa-ccache-sweep.timer'. 2025-05-07T18:06:14Z DEBUG step duration: httpd enable_ccache_sweep 0.44 sec 2025-05-07T18:06:14Z DEBUG [16/21]: configuring SELinux for httpd 2025-05-07T18:06:14Z DEBUG Starting external process 2025-05-07T18:06:14Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-05-07T18:06:14Z DEBUG Process finished, return code=0 2025-05-07T18:06:14Z DEBUG stdout= 2025-05-07T18:06:14Z DEBUG stderr= 2025-05-07T18:06:14Z DEBUG Starting external process 2025-05-07T18:06:14Z DEBUG args=['/usr/sbin/getsebool', 'httpd_can_network_connect'] 2025-05-07T18:06:14Z DEBUG Process finished, return code=0 2025-05-07T18:06:14Z DEBUG stdout=httpd_can_network_connect --> off 2025-05-07T18:06:14Z DEBUG stderr= 2025-05-07T18:06:14Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:14Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:14Z DEBUG Starting external process 2025-05-07T18:06:14Z DEBUG args=['/usr/sbin/getsebool', 'httpd_manage_ipa'] 2025-05-07T18:06:14Z DEBUG Process finished, return code=0 2025-05-07T18:06:14Z DEBUG stdout=httpd_manage_ipa --> off 2025-05-07T18:06:14Z DEBUG stderr= 2025-05-07T18:06:14Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:14Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:14Z DEBUG Starting external process 2025-05-07T18:06:14Z DEBUG args=['/usr/sbin/getsebool', 'httpd_run_ipa'] 2025-05-07T18:06:14Z DEBUG Process finished, return code=0 2025-05-07T18:06:14Z DEBUG stdout=httpd_run_ipa --> off 2025-05-07T18:06:14Z DEBUG stderr= 2025-05-07T18:06:14Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:14Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:14Z DEBUG Starting external process 2025-05-07T18:06:14Z DEBUG args=['/usr/sbin/getsebool', 'httpd_dbus_sssd'] 2025-05-07T18:06:14Z DEBUG Process finished, return code=0 2025-05-07T18:06:14Z DEBUG stdout=httpd_dbus_sssd --> off 2025-05-07T18:06:14Z DEBUG stderr= 2025-05-07T18:06:14Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:14Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:14Z DEBUG Starting external process 2025-05-07T18:06:14Z DEBUG args=['/usr/sbin/setsebool', '-P', 'httpd_can_network_connect=on', 'httpd_manage_ipa=on', 'httpd_run_ipa=on', 'httpd_dbus_sssd=on'] 2025-05-07T18:06:21Z DEBUG Process finished, return code=0 2025-05-07T18:06:21Z DEBUG stdout= 2025-05-07T18:06:21Z DEBUG stderr= 2025-05-07T18:06:21Z DEBUG step duration: httpd configure_selinux_for_httpd 7.04 sec 2025-05-07T18:06:21Z DEBUG [17/21]: create KDC proxy config 2025-05-07T18:06:21Z DEBUG Backing up system configuration file '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' 2025-05-07T18:06:21Z DEBUG -> Not backing up - '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' doesn't exist 2025-05-07T18:06:21Z DEBUG step duration: httpd create_kdcproxy_conf 0.00 sec 2025-05-07T18:06:21Z DEBUG [18/21]: enable KDC proxy 2025-05-07T18:06:21Z DEBUG update_entry modlist [(0, 'ipaconfigstring', [b'kdcProxyEnabled'])] 2025-05-07T18:06:21Z DEBUG service KDC has all config values set 2025-05-07T18:06:21Z DEBUG step duration: httpd enable_kdcproxy 0.02 sec 2025-05-07T18:06:21Z DEBUG [19/21]: starting httpd 2025-05-07T18:06:21Z DEBUG Starting external process 2025-05-07T18:06:21Z DEBUG args=['/bin/systemctl', 'start', 'httpd.service'] 2025-05-07T18:06:22Z DEBUG Process finished, return code=0 2025-05-07T18:06:22Z DEBUG stdout= 2025-05-07T18:06:22Z DEBUG stderr= 2025-05-07T18:06:22Z DEBUG Starting external process 2025-05-07T18:06:22Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2025-05-07T18:06:22Z DEBUG Process finished, return code=0 2025-05-07T18:06:22Z DEBUG stdout=active 2025-05-07T18:06:22Z DEBUG stderr= 2025-05-07T18:06:22Z DEBUG Start of httpd.service complete 2025-05-07T18:06:22Z DEBUG step duration: httpd start 0.77 sec 2025-05-07T18:06:22Z DEBUG [20/21]: configuring httpd to start on boot 2025-05-07T18:06:22Z DEBUG Starting external process 2025-05-07T18:06:22Z DEBUG args=['/bin/systemctl', 'is-enabled', 'httpd.service'] 2025-05-07T18:06:22Z DEBUG Process finished, return code=1 2025-05-07T18:06:22Z DEBUG stdout=disabled 2025-05-07T18:06:22Z DEBUG stderr= 2025-05-07T18:06:22Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:22Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:22Z DEBUG Starting external process 2025-05-07T18:06:22Z DEBUG args=['/bin/systemctl', 'unmask', 'httpd.service'] 2025-05-07T18:06:22Z DEBUG Process finished, return code=0 2025-05-07T18:06:22Z DEBUG stdout= 2025-05-07T18:06:22Z DEBUG stderr= 2025-05-07T18:06:22Z DEBUG Starting external process 2025-05-07T18:06:22Z DEBUG args=['/bin/systemctl', 'disable', 'httpd.service'] 2025-05-07T18:06:23Z DEBUG Process finished, return code=0 2025-05-07T18:06:23Z DEBUG stdout= 2025-05-07T18:06:23Z DEBUG stderr= 2025-05-07T18:06:23Z DEBUG step duration: httpd __enable 1.05 sec 2025-05-07T18:06:23Z DEBUG [21/21]: enabling oddjobd 2025-05-07T18:06:23Z DEBUG Starting external process 2025-05-07T18:06:23Z DEBUG args=['/bin/systemctl', 'is-active', 'oddjobd.service'] 2025-05-07T18:06:23Z DEBUG Process finished, return code=3 2025-05-07T18:06:23Z DEBUG stdout=inactive 2025-05-07T18:06:23Z DEBUG stderr= 2025-05-07T18:06:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:23Z DEBUG Starting external process 2025-05-07T18:06:23Z DEBUG args=['/bin/systemctl', 'is-enabled', 'oddjobd.service'] 2025-05-07T18:06:23Z DEBUG Process finished, return code=1 2025-05-07T18:06:23Z DEBUG stdout=disabled 2025-05-07T18:06:23Z DEBUG stderr= 2025-05-07T18:06:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:23Z DEBUG Starting external process 2025-05-07T18:06:23Z DEBUG args=['/bin/systemctl', 'enable', 'oddjobd.service'] 2025-05-07T18:06:23Z DEBUG Process finished, return code=0 2025-05-07T18:06:23Z DEBUG stdout= 2025-05-07T18:06:23Z DEBUG stderr=Created symlink '/etc/systemd/system/multi-user.target.wants/oddjobd.service' → '/usr/lib/systemd/system/oddjobd.service'. 2025-05-07T18:06:23Z DEBUG Starting external process 2025-05-07T18:06:23Z DEBUG args=['/bin/systemctl', 'start', 'oddjobd.service'] 2025-05-07T18:06:23Z DEBUG Process finished, return code=0 2025-05-07T18:06:23Z DEBUG stdout= 2025-05-07T18:06:23Z DEBUG stderr= 2025-05-07T18:06:23Z DEBUG Starting external process 2025-05-07T18:06:23Z DEBUG args=['/bin/systemctl', 'is-active', 'oddjobd.service'] 2025-05-07T18:06:23Z DEBUG Process finished, return code=0 2025-05-07T18:06:23Z DEBUG stdout=active 2025-05-07T18:06:23Z DEBUG stderr= 2025-05-07T18:06:23Z DEBUG Start of oddjobd.service complete 2025-05-07T18:06:23Z DEBUG step duration: httpd enable_and_start_oddjobd 0.62 sec 2025-05-07T18:06:23Z DEBUG Done configuring the web interface (httpd). 2025-05-07T18:06:23Z DEBUG service duration: httpd 13.02 sec 2025-05-07T18:06:23Z DEBUG Configuring Kerberos KDC (krb5kdc) 2025-05-07T18:06:23Z DEBUG [1/1]: installing X509 Certificate for PKINIT 2025-05-07T18:06:24Z DEBUG certmonger request is in state 'GENERATING_KEY_PAIR' 2025-05-07T18:06:24Z DEBUG certmonger request is in state 'SUBMITTING' 2025-05-07T18:06:25Z DEBUG certmonger request is in state 'POST_SAVED_CERT' 2025-05-07T18:06:26Z DEBUG certmonger request is in state 'MONITORING' 2025-05-07T18:06:26Z DEBUG Cert request 20250507180624 was successful 2025-05-07T18:06:26Z DEBUG update_entry modlist [(0, 'ipaconfigstring', [b'pkinitEnabled'])] 2025-05-07T18:06:26Z DEBUG service KDC has all config values set 2025-05-07T18:06:26Z DEBUG step duration: krb5kdc setup_pkinit 2.80 sec 2025-05-07T18:06:26Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2025-05-07T18:06:26Z DEBUG service duration: krb5kdc 2.80 sec 2025-05-07T18:06:26Z DEBUG Starting external process 2025-05-07T18:06:26Z DEBUG args=['/bin/systemctl', 'restart', 'krb5kdc.service'] 2025-05-07T18:06:26Z DEBUG Process finished, return code=0 2025-05-07T18:06:26Z DEBUG stdout= 2025-05-07T18:06:26Z DEBUG stderr= 2025-05-07T18:06:26Z DEBUG Starting external process 2025-05-07T18:06:26Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2025-05-07T18:06:27Z DEBUG Process finished, return code=0 2025-05-07T18:06:27Z DEBUG stdout=active 2025-05-07T18:06:27Z DEBUG stderr= 2025-05-07T18:06:27Z DEBUG Restart of krb5kdc.service complete 2025-05-07T18:06:27Z DEBUG Applying LDAP updates 2025-05-07T18:06:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:27Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:06:27Z DEBUG Starting external process 2025-05-07T18:06:27Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:06:27Z DEBUG Process finished, return code=0 2025-05-07T18:06:27Z DEBUG stdout=active 2025-05-07T18:06:27Z DEBUG stderr= 2025-05-07T18:06:27Z DEBUG Upgrading IPA:. Estimated time: 1 minute 30 seconds 2025-05-07T18:06:27Z DEBUG [1/10]: stopping directory server 2025-05-07T18:06:27Z DEBUG Destroyed connection context.ldap2_139937138938208 2025-05-07T18:06:27Z DEBUG Starting external process 2025-05-07T18:06:27Z DEBUG args=['/bin/systemctl', 'stop', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:06:27Z DEBUG Process finished, return code=0 2025-05-07T18:06:27Z DEBUG stdout= 2025-05-07T18:06:27Z DEBUG stderr= 2025-05-07T18:06:27Z DEBUG Stop of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:06:27Z DEBUG step duration: dirsrv __stop_instance 0.50 sec 2025-05-07T18:06:27Z DEBUG [2/10]: saving configuration 2025-05-07T18:06:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:27Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:27Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:27Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:27Z DEBUG step duration: dirsrv __save_config 0.03 sec 2025-05-07T18:06:27Z DEBUG [3/10]: disabling listeners 2025-05-07T18:06:27Z DEBUG step duration: dirsrv __disable_listeners 0.03 sec 2025-05-07T18:06:27Z DEBUG [4/10]: enabling DS global lock 2025-05-07T18:06:27Z DEBUG step duration: dirsrv __enable_ds_global_write_lock 0.03 sec 2025-05-07T18:06:27Z DEBUG [5/10]: disabling Schema Compat 2025-05-07T18:06:27Z DEBUG step duration: dirsrv __disable_schema_compat 0.01 sec 2025-05-07T18:06:27Z DEBUG [6/10]: starting directory server 2025-05-07T18:06:27Z DEBUG Starting external process 2025-05-07T18:06:27Z DEBUG args=['/bin/systemctl', 'start', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:06:28Z DEBUG Process finished, return code=0 2025-05-07T18:06:28Z DEBUG stdout= 2025-05-07T18:06:28Z DEBUG stderr= 2025-05-07T18:06:28Z DEBUG Start of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:06:28Z DEBUG Created connection context.ldap2_139937138938208 2025-05-07T18:06:28Z DEBUG step duration: dirsrv __start 0.94 sec 2025-05-07T18:06:28Z DEBUG [7/10]: upgrading server 2025-05-07T18:06:28Z DEBUG importing all plugin modules in ipaserver.plugins... 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.aci 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.automember 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.automount 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.baseldap 2025-05-07T18:06:28Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.baseuser 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.batch 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.ca 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.caacl 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.cert 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.certmap 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.certprofile 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.config 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.delegation 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.dns 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.dogtag 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.group 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.hbac 2025-05-07T18:06:28Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.hbactest 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.host 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.idp 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.idrange 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.idviews 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.internal 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.join 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.ldap2 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.location 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.migration 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.misc 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.netgroup 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.otp 2025-05-07T18:06:28Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.otptoken 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.passkeyconfig 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.passwd 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.permission 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.ping 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.pkinit 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.privilege 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.rabase 2025-05-07T18:06:28Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.role 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.schema 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.selfservice 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.server 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.serverrole 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.serverroles 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.service 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.session 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.stageuser 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.subid 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.sudo 2025-05-07T18:06:28Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.sudorule 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.topology 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.trust 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.user 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.vault 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.virtual 2025-05-07T18:06:28Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.whoami 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2025-05-07T18:06:28Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.dns 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_subid_support 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2025-05-07T18:06:28Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2025-05-07T18:06:29Z DEBUG Created connection context.ldap2_139937118245168 2025-05-07T18:06:29Z DEBUG raw: idrange_show('UFREEIPA.TEST_id_range', version='2.254') 2025-05-07T18:06:29Z DEBUG idrange_show('UFREEIPA.TEST_id_range', rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:06:29Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:06:29Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:06:29Z DEBUG Parsing update file '/usr/share/ipa/updates/05-pre_upgrade_plugins.update' 2025-05-07T18:06:29Z DEBUG Executing upgrade plugin: update_managed_post_first 2025-05-07T18:06:29Z DEBUG raw: update_managed_post_first 2025-05-07T18:06:29Z DEBUG Executing upgrade plugin: update_changelog_maxage 2025-05-07T18:06:29Z DEBUG raw: update_changelog_maxage 2025-05-07T18:06:29Z DEBUG Error retrieving: cn=changelog5,cn=config 2025-05-07T18:06:29Z DEBUG Executing upgrade plugin: update_replica_attribute_lists 2025-05-07T18:06:29Z DEBUG raw: update_replica_attribute_lists 2025-05-07T18:06:29Z DEBUG Start replication agreement exclude list update task 2025-05-07T18:06:29Z DEBUG raw: topologysuffix_find(None, version='2.254') 2025-05-07T18:06:29Z DEBUG topologysuffix_find(None, all=False, raw=False, version='2.254', pkey_only=False) 2025-05-07T18:06:29Z DEBUG raw: topologysegment_find('domain', None, all=True, version='2.254') 2025-05-07T18:06:29Z DEBUG topologysegment_find('domain', None, all=True, raw=False, version='2.254', pkey_only=False) 2025-05-07T18:06:29Z DEBUG Done updating agreements 2025-05-07T18:06:29Z DEBUG Executing upgrade plugin: update_passync_privilege_check 2025-05-07T18:06:29Z DEBUG raw: update_passync_privilege_check 2025-05-07T18:06:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:29Z DEBUG Check if there is existing PassSync privilege 2025-05-07T18:06:29Z DEBUG PassSync privilege not found, this is a new update 2025-05-07T18:06:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:29Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:29Z DEBUG Executing upgrade plugin: update_referint 2025-05-07T18:06:29Z DEBUG raw: update_referint 2025-05-07T18:06:29Z DEBUG Upgrading referential integrity plugin configuration 2025-05-07T18:06:29Z DEBUG Initial value: LDAPEntry(ipapython.dn.DN('cn=referential integrity postoperation,cn=plugins,cn=config'), {'cn': [b'referential integrity postoperation'], 'nsslapd-plugin-depends-on-type': [b'database'], 'nsslapd-pluginDescription': [b'referential integrity plugin'], 'nsslapd-pluginEnabled': [b'on'], 'nsslapd-pluginId': [b'referint'], 'nsslapd-pluginInitfunc': [b'referint_postop_init'], 'nsslapd-pluginPath': [b'libreferint-plugin'], 'nsslapd-pluginType': [b'betxnpostoperation'], 'nsslapd-pluginVendor': [b'389 Project'], 'nsslapd-pluginVersion': [b'3.1.2'], 'nsslapd-pluginprecedence': [b'40'], 'objectClass': [b'top', b'nsSlapdPlugin', b'extensibleObject'], 'referint-logfile': [b'/var/log/dirsrv/slapd-UFREEIPA-TEST/referint'], 'referint-membership-attr': [b'member', b'uniquemember', b'owner', b'seeAlso'], 'referint-update-delay': [b'0']}) 2025-05-07T18:06:29Z DEBUG Plugin already uses new style, skipping 2025-05-07T18:06:29Z DEBUG Executing upgrade plugin: update_uniqueness_plugins_to_new_syntax 2025-05-07T18:06:29Z DEBUG raw: update_uniqueness_plugins_to_new_syntax 2025-05-07T18:06:29Z DEBUG No uniqueness plugin entries with old style configuration found 2025-05-07T18:06:29Z DEBUG LDAP update duration: /usr/share/ipa/updates/05-pre_upgrade_plugins.update 0.069 sec 2025-05-07T18:06:29Z DEBUG Parsing update file '/usr/share/ipa/updates/10-config.update' 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 2000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG only: set nsslapd-ssl-check-hostname to 'on', current value ['on'] 2025-05-07T18:06:29Z DEBUG only: updated value ['on'] 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 2000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG [] 2025-05-07T18:06:29Z DEBUG Updated 0 2025-05-07T18:06:29Z DEBUG Done 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG Kerberos Principal Name 2025-05-07T18:06:29Z DEBUG ipamodrdnfilter: 2025-05-07T18:06:29Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2025-05-07T18:06:29Z DEBUG ipamodrdnscope: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG ipamodrdnsourceattr: 2025-05-07T18:06:29Z DEBUG uid 2025-05-07T18:06:29Z DEBUG ipamodrdnsuffix: 2025-05-07T18:06:29Z DEBUG @UFREEIPA.TEST 2025-05-07T18:06:29Z DEBUG ipamodrdntargetattr: 2025-05-07T18:06:29Z DEBUG krbPrincipalName 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG remove: '60' from nsslapd-pluginPrecedence, current value [] 2025-05-07T18:06:29Z DEBUG remove: '60' not in nsslapd-pluginPrecedence 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG Kerberos Principal Name 2025-05-07T18:06:29Z DEBUG ipamodrdnfilter: 2025-05-07T18:06:29Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2025-05-07T18:06:29Z DEBUG ipamodrdnscope: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG ipamodrdnsourceattr: 2025-05-07T18:06:29Z DEBUG uid 2025-05-07T18:06:29Z DEBUG ipamodrdnsuffix: 2025-05-07T18:06:29Z DEBUG @UFREEIPA.TEST 2025-05-07T18:06:29Z DEBUG ipamodrdntargetattr: 2025-05-07T18:06:29Z DEBUG krbPrincipalName 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG [] 2025-05-07T18:06:29Z DEBUG Updated 0 2025-05-07T18:06:29Z DEBUG Done 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG IPA MODRDN 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:29Z DEBUG database 2025-05-07T18:06:29Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:29Z DEBUG IPA MODRDN plugin 2025-05-07T18:06:29Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:29Z DEBUG IPA MODRDN 2025-05-07T18:06:29Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:29Z DEBUG ipamodrdn_init 2025-05-07T18:06:29Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:29Z DEBUG libipa_modrdn 2025-05-07T18:06:29Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:29Z DEBUG betxnpostoperation 2025-05-07T18:06:29Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:29Z DEBUG Red Hat, Inc. 2025-05-07T18:06:29Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:29Z DEBUG 1.0 2025-05-07T18:06:29Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG nsSlapdPlugin 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value ['60'] 2025-05-07T18:06:29Z DEBUG only: updated value ['60'] 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG IPA MODRDN 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:29Z DEBUG database 2025-05-07T18:06:29Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:29Z DEBUG IPA MODRDN plugin 2025-05-07T18:06:29Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:29Z DEBUG IPA MODRDN 2025-05-07T18:06:29Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:29Z DEBUG ipamodrdn_init 2025-05-07T18:06:29Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:29Z DEBUG libipa_modrdn 2025-05-07T18:06:29Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:29Z DEBUG betxnpostoperation 2025-05-07T18:06:29Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:29Z DEBUG Red Hat, Inc. 2025-05-07T18:06:29Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:29Z DEBUG 1.0 2025-05-07T18:06:29Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG nsSlapdPlugin 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG [] 2025-05-07T18:06:29Z DEBUG Updated 0 2025-05-07T18:06:29Z DEBUG Done 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 2000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG replace: updated value ['100000'] 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG [(2, 'nsslapd-sizelimit', ['100000'])] 2025-05-07T18:06:29Z DEBUG Updated 1 2025-05-07T18:06:29Z DEBUG update_entry modlist [(2, 'nsslapd-sizelimit', [b'100000'])] 2025-05-07T18:06:29Z DEBUG Done 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG nsslapd-db-home-directory: 2025-05-07T18:06:29Z DEBUG /dev/shm/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapd-lookthroughlimit: 2025-05-07T18:06:29Z DEBUG 5000 2025-05-07T18:06:29Z DEBUG nsslapd-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-idlistscanlimit: 2025-05-07T18:06:29Z DEBUG 2147483646 2025-05-07T18:06:29Z DEBUG nsslapd-directory: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/db 2025-05-07T18:06:29Z DEBUG nsslapd-import-cachesize: 2025-05-07T18:06:29Z DEBUG 16777216 2025-05-07T18:06:29Z DEBUG nsslapd-idl-switch: 2025-05-07T18:06:29Z DEBUG new 2025-05-07T18:06:29Z DEBUG nsslapd-search-bypass-filter-test: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-search-use-vlv-index: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-exclude-from-export: 2025-05-07T18:06:29Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2025-05-07T18:06:29Z DEBUG nsslapd-serial-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-subtree-rename-switch: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-pagedlookthroughlimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-pagedidlistscanlimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-rangelookthroughlimit: 2025-05-07T18:06:29Z DEBUG 5000 2025-05-07T18:06:29Z DEBUG nsslapd-backend-opt-level: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-backend-implement: 2025-05-07T18:06:29Z DEBUG mdb 2025-05-07T18:06:29Z DEBUG replace: updated value ['100000'] 2025-05-07T18:06:29Z DEBUG replace: 4000 not found, skipping 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG nsslapd-db-home-directory: 2025-05-07T18:06:29Z DEBUG /dev/shm/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapd-lookthroughlimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-idlistscanlimit: 2025-05-07T18:06:29Z DEBUG 2147483646 2025-05-07T18:06:29Z DEBUG nsslapd-directory: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/db 2025-05-07T18:06:29Z DEBUG nsslapd-import-cachesize: 2025-05-07T18:06:29Z DEBUG 16777216 2025-05-07T18:06:29Z DEBUG nsslapd-idl-switch: 2025-05-07T18:06:29Z DEBUG new 2025-05-07T18:06:29Z DEBUG nsslapd-search-bypass-filter-test: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-search-use-vlv-index: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-exclude-from-export: 2025-05-07T18:06:29Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2025-05-07T18:06:29Z DEBUG nsslapd-serial-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-subtree-rename-switch: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-pagedlookthroughlimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-pagedidlistscanlimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-rangelookthroughlimit: 2025-05-07T18:06:29Z DEBUG 5000 2025-05-07T18:06:29Z DEBUG nsslapd-backend-opt-level: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-backend-implement: 2025-05-07T18:06:29Z DEBUG mdb 2025-05-07T18:06:29Z DEBUG [(2, 'nsslapd-lookthroughlimit', ['100000'])] 2025-05-07T18:06:29Z DEBUG Updated 1 2025-05-07T18:06:29Z DEBUG update_entry modlist [(2, 'nsslapd-lookthroughlimit', [b'100000'])] 2025-05-07T18:06:29Z DEBUG Done 2025-05-07T18:06:29Z DEBUG New entry: cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG objectclass: 2025-05-07T18:06:29Z DEBUG nsContainer 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG anonymous-limits 2025-05-07T18:06:29Z DEBUG nsSizeLimit: 2025-05-07T18:06:29Z DEBUG 5000 2025-05-07T18:06:29Z DEBUG nsLookThroughLimit: 2025-05-07T18:06:29Z DEBUG 5000 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG objectclass: 2025-05-07T18:06:29Z DEBUG nsContainer 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG anonymous-limits 2025-05-07T18:06:29Z DEBUG nsSizeLimit: 2025-05-07T18:06:29Z DEBUG 5000 2025-05-07T18:06:29Z DEBUG nsLookThroughLimit: 2025-05-07T18:06:29Z DEBUG 5000 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG only: set nsslapd-anonlimitsdn to 'cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test', current value [''] 2025-05-07T18:06:29Z DEBUG only: updated value ['cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG [(2, 'nsslapd-anonlimitsdn', ['cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:29Z DEBUG Updated 1 2025-05-07T18:06:29Z DEBUG update_entry modlist [(2, 'nsslapd-anonlimitsdn', [b'cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:29Z DEBUG Done 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG add: 'dc=ufreeipa,dc=test' to nsslapd-defaultNamingContext, current value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:29Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG [] 2025-05-07T18:06:29Z DEBUG Updated 0 2025-05-07T18:06:29Z DEBUG Done 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG only: set nsslapd-minssf-exclude-rootdse to 'on', current value ['off'] 2025-05-07T18:06:29Z DEBUG only: updated value ['on'] 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG [(2, 'nsslapd-minssf-exclude-rootdse', ['on'])] 2025-05-07T18:06:29Z DEBUG Updated 1 2025-05-07T18:06:29Z DEBUG update_entry modlist [(2, 'nsslapd-minssf-exclude-rootdse', [b'on'])] 2025-05-07T18:06:29Z DEBUG Done 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG ipa-winsync 2025-05-07T18:06:29Z DEBUG ipawinsyncacctdisable: 2025-05-07T18:06:29Z DEBUG both 2025-05-07T18:06:29Z DEBUG ipawinsyncdefaultgroupattr: 2025-05-07T18:06:29Z DEBUG ipaDefaultPrimaryGroup 2025-05-07T18:06:29Z DEBUG ipawinsyncdefaultgroupfilter: 2025-05-07T18:06:29Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2025-05-07T18:06:29Z DEBUG ipawinsyncforcesync: 2025-05-07T18:06:29Z DEBUG true 2025-05-07T18:06:29Z DEBUG ipawinsynchomedirattr: 2025-05-07T18:06:29Z DEBUG ipaHomesRootDir 2025-05-07T18:06:29Z DEBUG ipawinsyncloginshellattr: 2025-05-07T18:06:29Z DEBUG ipaDefaultLoginShell 2025-05-07T18:06:29Z DEBUG ipawinsyncnewentryfilter: 2025-05-07T18:06:29Z DEBUG (cn=ipaConfig) 2025-05-07T18:06:29Z DEBUG ipawinsyncnewuserocattr: 2025-05-07T18:06:29Z DEBUG ipauserobjectclasses 2025-05-07T18:06:29Z DEBUG ipawinsyncrealmattr: 2025-05-07T18:06:29Z DEBUG cn 2025-05-07T18:06:29Z DEBUG ipawinsyncrealmfilter: 2025-05-07T18:06:29Z DEBUG (objectclass=krbRealmContainer) 2025-05-07T18:06:29Z DEBUG ipawinsyncuserattr: 2025-05-07T18:06:29Z DEBUG uidNumber -1 2025-05-07T18:06:29Z DEBUG gidNumber -1 2025-05-07T18:06:29Z DEBUG ipawinsyncuserflatten: 2025-05-07T18:06:29Z DEBUG true 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:29Z DEBUG database 2025-05-07T18:06:29Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:29Z DEBUG ipa winsync plugin 2025-05-07T18:06:29Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:29Z DEBUG ipa-winsync-plugin 2025-05-07T18:06:29Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:29Z DEBUG ipa_winsync_plugin_init 2025-05-07T18:06:29Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:29Z DEBUG libipa_winsync 2025-05-07T18:06:29Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:29Z DEBUG preoperation 2025-05-07T18:06:29Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:29Z DEBUG FreeIPA project 2025-05-07T18:06:29Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:29Z DEBUG FreeIPA/1.0 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG nsSlapdPlugin 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [] 2025-05-07T18:06:29Z DEBUG only: updated value ['60'] 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG ipa-winsync 2025-05-07T18:06:29Z DEBUG ipawinsyncacctdisable: 2025-05-07T18:06:29Z DEBUG both 2025-05-07T18:06:29Z DEBUG ipawinsyncdefaultgroupattr: 2025-05-07T18:06:29Z DEBUG ipaDefaultPrimaryGroup 2025-05-07T18:06:29Z DEBUG ipawinsyncdefaultgroupfilter: 2025-05-07T18:06:29Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2025-05-07T18:06:29Z DEBUG ipawinsyncforcesync: 2025-05-07T18:06:29Z DEBUG true 2025-05-07T18:06:29Z DEBUG ipawinsynchomedirattr: 2025-05-07T18:06:29Z DEBUG ipaHomesRootDir 2025-05-07T18:06:29Z DEBUG ipawinsyncloginshellattr: 2025-05-07T18:06:29Z DEBUG ipaDefaultLoginShell 2025-05-07T18:06:29Z DEBUG ipawinsyncnewentryfilter: 2025-05-07T18:06:29Z DEBUG (cn=ipaConfig) 2025-05-07T18:06:29Z DEBUG ipawinsyncnewuserocattr: 2025-05-07T18:06:29Z DEBUG ipauserobjectclasses 2025-05-07T18:06:29Z DEBUG ipawinsyncrealmattr: 2025-05-07T18:06:29Z DEBUG cn 2025-05-07T18:06:29Z DEBUG ipawinsyncrealmfilter: 2025-05-07T18:06:29Z DEBUG (objectclass=krbRealmContainer) 2025-05-07T18:06:29Z DEBUG ipawinsyncuserattr: 2025-05-07T18:06:29Z DEBUG uidNumber -1 2025-05-07T18:06:29Z DEBUG gidNumber -1 2025-05-07T18:06:29Z DEBUG ipawinsyncuserflatten: 2025-05-07T18:06:29Z DEBUG true 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:29Z DEBUG database 2025-05-07T18:06:29Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:29Z DEBUG ipa winsync plugin 2025-05-07T18:06:29Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:29Z DEBUG ipa-winsync-plugin 2025-05-07T18:06:29Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:29Z DEBUG ipa_winsync_plugin_init 2025-05-07T18:06:29Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:29Z DEBUG libipa_winsync 2025-05-07T18:06:29Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:29Z DEBUG preoperation 2025-05-07T18:06:29Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:29Z DEBUG FreeIPA project 2025-05-07T18:06:29Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:29Z DEBUG FreeIPA/1.0 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG nsSlapdPlugin 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapd-pluginPrecedence: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG [(2, 'nsslapd-pluginPrecedence', ['60'])] 2025-05-07T18:06:29Z DEBUG Updated 1 2025-05-07T18:06:29Z DEBUG update_entry modlist [(2, 'nsslapd-pluginPrecedence', [b'60'])] 2025-05-07T18:06:29Z DEBUG Done 2025-05-07T18:06:29Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Initial value 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:29Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:29Z DEBUG passwordChange: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:29Z DEBUG 256 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securePort: 2025-05-07T18:06:29Z DEBUG 636 2025-05-07T18:06:29Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:29Z DEBUG 185 2025-05-07T18:06:29Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordExp: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG day 2025-05-07T18:06:29Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-nagle: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:29Z DEBUG default 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:29Z DEBUG %FT%TZ 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:29Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:29Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:29Z DEBUG uidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:29Z DEBUG gidNumber 2025-05-07T18:06:29Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:29Z DEBUG dc=example,dc=com 2025-05-07T18:06:29Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:29Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:29Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-counters: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:29Z DEBUG cn=Directory Manager 2025-05-07T18:06:29Z DEBUG passwordMinAge: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:29Z DEBUG 209715200 2025-05-07T18:06:29Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:29Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:29Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:29Z DEBUG 524288 2025-05-07T18:06:29Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:29Z DEBUG allowed 2025-05-07T18:06:29Z DEBUG nsslapd-config: 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:29Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:29Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:29Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:29Z DEBUG /tmp 2025-05-07T18:06:29Z DEBUG nsslapd-certdir: 2025-05-07T18:06:29Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:29Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:29Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:29Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rundir: 2025-05-07T18:06:29Z DEBUG /run/dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:29Z DEBUG 300000 2025-05-07T18:06:29Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-localssf: 2025-05-07T18:06:29Z DEBUG 71 2025-05-07T18:06:29Z DEBUG nsslapd-minssf: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:29Z DEBUG next 2025-05-07T18:06:29Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:29Z DEBUG warn 2025-05-07T18:06:29Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:29Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:29Z DEBUG 60 2025-05-07T18:06:29Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:29Z DEBUG 20971520 2025-05-07T18:06:29Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:29Z DEBUG nolog 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:29Z DEBUG 2097152 2025-05-07T18:06:29Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:29Z DEBUG 128 2025-05-07T18:06:29Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:29Z DEBUG -10 2025-05-07T18:06:29Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 2 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:29Z DEBUG month 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:29Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:29Z DEBUG dirsrv-log 2025-05-07T18:06:29Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:29Z DEBUG none 2025-05-07T18:06:29Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:29Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:29Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:29Z DEBUG process-safe 2025-05-07T18:06:29Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:29Z DEBUG 3600 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:29Z DEBUG 30 2025-05-07T18:06:29Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:29Z DEBUG 300 2025-05-07T18:06:29Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordStorageScheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG passwordAdminDN: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:29Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:29Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:29Z DEBUG aci: 2025-05-07T18:06:29Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:29Z DEBUG only: set nsslapd-sasl-mapping-fallback to 'on', current value ['on'] 2025-05-07T18:06:29Z DEBUG only: updated value ['on'] 2025-05-07T18:06:29Z DEBUG --------------------------------------------- 2025-05-07T18:06:29Z DEBUG Final value after applying updates 2025-05-07T18:06:29Z DEBUG dn: cn=config 2025-05-07T18:06:29Z DEBUG cn: 2025-05-07T18:06:29Z DEBUG config 2025-05-07T18:06:29Z DEBUG objectClass: 2025-05-07T18:06:29Z DEBUG top 2025-05-07T18:06:29Z DEBUG extensibleObject 2025-05-07T18:06:29Z DEBUG nsslapdConfig 2025-05-07T18:06:29Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:29Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-betype: 2025-05-07T18:06:29Z DEBUG ldbm database 2025-05-07T18:06:29Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:29Z DEBUG cn=schema 2025-05-07T18:06:29Z DEBUG cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-plugin: 2025-05-07T18:06:29Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:29Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:29Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:29Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:29Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:29Z DEBUG 10 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:29Z DEBUG 8192 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-port: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:29Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:29Z DEBUG 5 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-localuser: 2025-05-07T18:06:29Z DEBUG dirsrv 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordInHistory: 2025-05-07T18:06:29Z DEBUG 6 2025-05-07T18:06:29Z DEBUG passwordUnlock: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordGraceLimit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG passwordMustChange: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:29Z DEBUG 100000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordWarning: 2025-05-07T18:06:29Z DEBUG 86400 2025-05-07T18:06:29Z DEBUG nsslapd-readonly: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:29Z DEBUG 16 2025-05-07T18:06:29Z DEBUG passwordLockout: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-localhost: 2025-05-07T18:06:29Z DEBUG master.ufreeipa.test 2025-05-07T18:06:29Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:29Z DEBUG 10000 2025-05-07T18:06:29Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:29Z DEBUG 40 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 100 2025-05-07T18:06:29Z DEBUG passwordMinLength: 2025-05-07T18:06:29Z DEBUG 8 2025-05-07T18:06:29Z DEBUG passwordMinDigits: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinAlphas: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinUppers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinLowers: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinSpecials: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMin8bit: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMinCategories: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG passwordPalindrome: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictCheck: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordDictPath: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordUserAttributes: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordBadWords: 2025-05-07T18:06:29Z DEBUG 2025-05-07T18:06:29Z DEBUG passwordMaxSequence: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:29Z DEBUG 0 2025-05-07T18:06:29Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:29Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:29Z DEBUG 1 2025-05-07T18:06:29Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:29Z DEBUG replication-only 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:29Z DEBUG 500 2025-05-07T18:06:29Z DEBUG passwordMaxFailure: 2025-05-07T18:06:29Z DEBUG 3 2025-05-07T18:06:29Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:29Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:29Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG nsslapd-security: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordMaxAge: 2025-05-07T18:06:29Z DEBUG 8640000 2025-05-07T18:06:29Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:29Z DEBUG week 2025-05-07T18:06:29Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:29Z DEBUG 600 2025-05-07T18:06:29Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:29Z DEBUG -1 2025-05-07T18:06:29Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:29Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:29Z DEBUG on 2025-05-07T18:06:29Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:29Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:30Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:30Z DEBUG passwordChange: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securePort: 2025-05-07T18:06:30Z DEBUG 636 2025-05-07T18:06:30Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:30Z DEBUG 185 2025-05-07T18:06:30Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordExp: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG day 2025-05-07T18:06:30Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-nagle: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:30Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:30Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:30Z DEBUG uidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:30Z DEBUG gidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:30Z DEBUG dc=example,dc=com 2025-05-07T18:06:30Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:30Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:30Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-counters: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG passwordMinAge: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:30Z DEBUG 209715200 2025-05-07T18:06:30Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:30Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:30Z DEBUG 524288 2025-05-07T18:06:30Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:30Z DEBUG allowed 2025-05-07T18:06:30Z DEBUG nsslapd-config: 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:30Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:30Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:30Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:30Z DEBUG /tmp 2025-05-07T18:06:30Z DEBUG nsslapd-certdir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:30Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:30Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rundir: 2025-05-07T18:06:30Z DEBUG /run/dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:30Z DEBUG 300000 2025-05-07T18:06:30Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-localssf: 2025-05-07T18:06:30Z DEBUG 71 2025-05-07T18:06:30Z DEBUG nsslapd-minssf: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:30Z DEBUG next 2025-05-07T18:06:30Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:30Z DEBUG warn 2025-05-07T18:06:30Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:30Z DEBUG 20971520 2025-05-07T18:06:30Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:30Z DEBUG nolog 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:30Z DEBUG 128 2025-05-07T18:06:30Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:30Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:30Z DEBUG dirsrv-log 2025-05-07T18:06:30Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:30Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:30Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:30Z DEBUG process-safe 2025-05-07T18:06:30Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:30Z DEBUG 30 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordStorageScheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG passwordAdminDN: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:30Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:30Z DEBUG aci: 2025-05-07T18:06:30Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Full Principal 2025-05-07T18:06:30Z DEBUG nsSaslMapBaseDNTemplate: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsSaslMapFilterTemplate: 2025-05-07T18:06:30Z DEBUG (krbPrincipalName=\1@\2) 2025-05-07T18:06:30Z DEBUG nsSaslMapPriority: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsSaslMapRegexString: 2025-05-07T18:06:30Z DEBUG \(.*\)@\(.*\) 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSaslMapping 2025-05-07T18:06:30Z DEBUG addifnew: '10' to nsSaslMapPriority, current value ['10'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Full Principal 2025-05-07T18:06:30Z DEBUG nsSaslMapBaseDNTemplate: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsSaslMapFilterTemplate: 2025-05-07T18:06:30Z DEBUG (krbPrincipalName=\1@\2) 2025-05-07T18:06:30Z DEBUG nsSaslMapPriority: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsSaslMapRegexString: 2025-05-07T18:06:30Z DEBUG \(.*\)@\(.*\) 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSaslMapping 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=Name Only,cn=mapping,cn=sasl,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Name Only 2025-05-07T18:06:30Z DEBUG nsSaslMapBaseDNTemplate: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsSaslMapFilterTemplate: 2025-05-07T18:06:30Z DEBUG (krbPrincipalName=&@UFREEIPA.TEST) 2025-05-07T18:06:30Z DEBUG nsSaslMapPriority: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsSaslMapRegexString: 2025-05-07T18:06:30Z DEBUG ^[^:@]+$ 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSaslMapping 2025-05-07T18:06:30Z DEBUG addifnew: '10' to nsSaslMapPriority, current value ['10'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Name Only 2025-05-07T18:06:30Z DEBUG nsSaslMapBaseDNTemplate: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsSaslMapFilterTemplate: 2025-05-07T18:06:30Z DEBUG (krbPrincipalName=&@UFREEIPA.TEST) 2025-05-07T18:06:30Z DEBUG nsSaslMapPriority: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsSaslMapRegexString: 2025-05-07T18:06:30Z DEBUG ^[^:@]+$ 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSaslMapping 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG config 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsslapdConfig 2025-05-07T18:06:30Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:30Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-betype: 2025-05-07T18:06:30Z DEBUG ldbm database 2025-05-07T18:06:30Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:30Z DEBUG cn=schema 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-plugin: 2025-05-07T18:06:30Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:30Z DEBUG 8192 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-port: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-localuser: 2025-05-07T18:06:30Z DEBUG dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordInHistory: 2025-05-07T18:06:30Z DEBUG 6 2025-05-07T18:06:30Z DEBUG passwordUnlock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordGraceLimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordMustChange: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:30Z DEBUG 100000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordWarning: 2025-05-07T18:06:30Z DEBUG 86400 2025-05-07T18:06:30Z DEBUG nsslapd-readonly: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:30Z DEBUG 16 2025-05-07T18:06:30Z DEBUG passwordLockout: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-localhost: 2025-05-07T18:06:30Z DEBUG master.ufreeipa.test 2025-05-07T18:06:30Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:30Z DEBUG 10000 2025-05-07T18:06:30Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:30Z DEBUG 40 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordMinLength: 2025-05-07T18:06:30Z DEBUG 8 2025-05-07T18:06:30Z DEBUG passwordMinDigits: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinAlphas: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinUppers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinLowers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinSpecials: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMin8bit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinCategories: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordPalindrome: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictCheck: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictPath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordUserAttributes: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordBadWords: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordMaxSequence: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:30Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:30Z DEBUG replication-only 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG passwordMaxFailure: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:30Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-security: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordMaxAge: 2025-05-07T18:06:30Z DEBUG 8640000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:30Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:30Z DEBUG passwordChange: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securePort: 2025-05-07T18:06:30Z DEBUG 636 2025-05-07T18:06:30Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:30Z DEBUG 185 2025-05-07T18:06:30Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordExp: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG day 2025-05-07T18:06:30Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-nagle: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:30Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:30Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:30Z DEBUG uidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:30Z DEBUG gidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:30Z DEBUG dc=example,dc=com 2025-05-07T18:06:30Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:30Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:30Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-counters: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG passwordMinAge: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:30Z DEBUG 209715200 2025-05-07T18:06:30Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:30Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:30Z DEBUG 524288 2025-05-07T18:06:30Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:30Z DEBUG allowed 2025-05-07T18:06:30Z DEBUG nsslapd-config: 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:30Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:30Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:30Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:30Z DEBUG /tmp 2025-05-07T18:06:30Z DEBUG nsslapd-certdir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:30Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:30Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rundir: 2025-05-07T18:06:30Z DEBUG /run/dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:30Z DEBUG 300000 2025-05-07T18:06:30Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-localssf: 2025-05-07T18:06:30Z DEBUG 71 2025-05-07T18:06:30Z DEBUG nsslapd-minssf: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:30Z DEBUG next 2025-05-07T18:06:30Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:30Z DEBUG warn 2025-05-07T18:06:30Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:30Z DEBUG 20971520 2025-05-07T18:06:30Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:30Z DEBUG nolog 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:30Z DEBUG 128 2025-05-07T18:06:30Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:30Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:30Z DEBUG dirsrv-log 2025-05-07T18:06:30Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:30Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:30Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:30Z DEBUG process-safe 2025-05-07T18:06:30Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:30Z DEBUG 30 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordStorageScheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG passwordAdminDN: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:30Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:30Z DEBUG aci: 2025-05-07T18:06:30Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:30Z DEBUG only: set nsslapd-allow-hashed-passwords to 'on', current value ['off'] 2025-05-07T18:06:30Z DEBUG only: updated value ['on'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG config 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsslapdConfig 2025-05-07T18:06:30Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:30Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-betype: 2025-05-07T18:06:30Z DEBUG ldbm database 2025-05-07T18:06:30Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:30Z DEBUG cn=schema 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-plugin: 2025-05-07T18:06:30Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:30Z DEBUG 8192 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-port: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-localuser: 2025-05-07T18:06:30Z DEBUG dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordInHistory: 2025-05-07T18:06:30Z DEBUG 6 2025-05-07T18:06:30Z DEBUG passwordUnlock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordGraceLimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordMustChange: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:30Z DEBUG 100000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordWarning: 2025-05-07T18:06:30Z DEBUG 86400 2025-05-07T18:06:30Z DEBUG nsslapd-readonly: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:30Z DEBUG 16 2025-05-07T18:06:30Z DEBUG passwordLockout: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-localhost: 2025-05-07T18:06:30Z DEBUG master.ufreeipa.test 2025-05-07T18:06:30Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:30Z DEBUG 10000 2025-05-07T18:06:30Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:30Z DEBUG 40 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordMinLength: 2025-05-07T18:06:30Z DEBUG 8 2025-05-07T18:06:30Z DEBUG passwordMinDigits: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinAlphas: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinUppers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinLowers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinSpecials: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMin8bit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinCategories: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordPalindrome: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictCheck: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictPath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordUserAttributes: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordBadWords: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordMaxSequence: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:30Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:30Z DEBUG replication-only 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG passwordMaxFailure: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:30Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-security: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordMaxAge: 2025-05-07T18:06:30Z DEBUG 8640000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:30Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:30Z DEBUG passwordChange: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securePort: 2025-05-07T18:06:30Z DEBUG 636 2025-05-07T18:06:30Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:30Z DEBUG 185 2025-05-07T18:06:30Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordExp: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG day 2025-05-07T18:06:30Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-nagle: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:30Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:30Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:30Z DEBUG uidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:30Z DEBUG gidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:30Z DEBUG dc=example,dc=com 2025-05-07T18:06:30Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:30Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:30Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-counters: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG passwordMinAge: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:30Z DEBUG 209715200 2025-05-07T18:06:30Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:30Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:30Z DEBUG 524288 2025-05-07T18:06:30Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:30Z DEBUG allowed 2025-05-07T18:06:30Z DEBUG nsslapd-config: 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:30Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:30Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:30Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:30Z DEBUG /tmp 2025-05-07T18:06:30Z DEBUG nsslapd-certdir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:30Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:30Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rundir: 2025-05-07T18:06:30Z DEBUG /run/dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:30Z DEBUG 300000 2025-05-07T18:06:30Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-localssf: 2025-05-07T18:06:30Z DEBUG 71 2025-05-07T18:06:30Z DEBUG nsslapd-minssf: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:30Z DEBUG next 2025-05-07T18:06:30Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:30Z DEBUG warn 2025-05-07T18:06:30Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:30Z DEBUG 20971520 2025-05-07T18:06:30Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:30Z DEBUG nolog 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:30Z DEBUG 128 2025-05-07T18:06:30Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:30Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:30Z DEBUG dirsrv-log 2025-05-07T18:06:30Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:30Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:30Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:30Z DEBUG process-safe 2025-05-07T18:06:30Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:30Z DEBUG 30 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordStorageScheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG passwordAdminDN: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:30Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:30Z DEBUG aci: 2025-05-07T18:06:30Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:30Z DEBUG [(2, 'nsslapd-allow-hashed-passwords', ['on'])] 2025-05-07T18:06:30Z DEBUG Updated 1 2025-05-07T18:06:30Z DEBUG update_entry modlist [(2, 'nsslapd-allow-hashed-passwords', [b'on'])] 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG config 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsslapdConfig 2025-05-07T18:06:30Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:30Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-betype: 2025-05-07T18:06:30Z DEBUG ldbm database 2025-05-07T18:06:30Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:30Z DEBUG cn=schema 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-plugin: 2025-05-07T18:06:30Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:30Z DEBUG 8192 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-port: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-localuser: 2025-05-07T18:06:30Z DEBUG dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordInHistory: 2025-05-07T18:06:30Z DEBUG 6 2025-05-07T18:06:30Z DEBUG passwordUnlock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordGraceLimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordMustChange: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:30Z DEBUG 100000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordWarning: 2025-05-07T18:06:30Z DEBUG 86400 2025-05-07T18:06:30Z DEBUG nsslapd-readonly: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:30Z DEBUG 16 2025-05-07T18:06:30Z DEBUG passwordLockout: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-localhost: 2025-05-07T18:06:30Z DEBUG master.ufreeipa.test 2025-05-07T18:06:30Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:30Z DEBUG 10000 2025-05-07T18:06:30Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:30Z DEBUG 40 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordMinLength: 2025-05-07T18:06:30Z DEBUG 8 2025-05-07T18:06:30Z DEBUG passwordMinDigits: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinAlphas: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinUppers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinLowers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinSpecials: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMin8bit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinCategories: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordPalindrome: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictCheck: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictPath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordUserAttributes: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordBadWords: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordMaxSequence: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:30Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:30Z DEBUG replication-only 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG passwordMaxFailure: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:30Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-security: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordMaxAge: 2025-05-07T18:06:30Z DEBUG 8640000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:30Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:30Z DEBUG passwordChange: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securePort: 2025-05-07T18:06:30Z DEBUG 636 2025-05-07T18:06:30Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:30Z DEBUG 185 2025-05-07T18:06:30Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordExp: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG day 2025-05-07T18:06:30Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-nagle: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:30Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:30Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:30Z DEBUG uidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:30Z DEBUG gidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:30Z DEBUG dc=example,dc=com 2025-05-07T18:06:30Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:30Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:30Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-counters: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG passwordMinAge: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:30Z DEBUG 209715200 2025-05-07T18:06:30Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:30Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:30Z DEBUG 524288 2025-05-07T18:06:30Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:30Z DEBUG allowed 2025-05-07T18:06:30Z DEBUG nsslapd-config: 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:30Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:30Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:30Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:30Z DEBUG /tmp 2025-05-07T18:06:30Z DEBUG nsslapd-certdir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:30Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:30Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rundir: 2025-05-07T18:06:30Z DEBUG /run/dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:30Z DEBUG 300000 2025-05-07T18:06:30Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-localssf: 2025-05-07T18:06:30Z DEBUG 71 2025-05-07T18:06:30Z DEBUG nsslapd-minssf: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:30Z DEBUG next 2025-05-07T18:06:30Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:30Z DEBUG warn 2025-05-07T18:06:30Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:30Z DEBUG 20971520 2025-05-07T18:06:30Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:30Z DEBUG nolog 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:30Z DEBUG 128 2025-05-07T18:06:30Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:30Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:30Z DEBUG dirsrv-log 2025-05-07T18:06:30Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:30Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:30Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:30Z DEBUG process-safe 2025-05-07T18:06:30Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:30Z DEBUG 30 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordStorageScheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG passwordAdminDN: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:30Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:30Z DEBUG aci: 2025-05-07T18:06:30Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:30Z DEBUG only: set nsslapd-ioblocktimeout to '10000', current value ['10000'] 2025-05-07T18:06:30Z DEBUG only: updated value ['10000'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG config 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsslapdConfig 2025-05-07T18:06:30Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:30Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-betype: 2025-05-07T18:06:30Z DEBUG ldbm database 2025-05-07T18:06:30Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:30Z DEBUG cn=schema 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-plugin: 2025-05-07T18:06:30Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:30Z DEBUG 8192 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-port: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-localuser: 2025-05-07T18:06:30Z DEBUG dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordInHistory: 2025-05-07T18:06:30Z DEBUG 6 2025-05-07T18:06:30Z DEBUG passwordUnlock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordGraceLimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordMustChange: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:30Z DEBUG 100000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordWarning: 2025-05-07T18:06:30Z DEBUG 86400 2025-05-07T18:06:30Z DEBUG nsslapd-readonly: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:30Z DEBUG 16 2025-05-07T18:06:30Z DEBUG passwordLockout: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-localhost: 2025-05-07T18:06:30Z DEBUG master.ufreeipa.test 2025-05-07T18:06:30Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:30Z DEBUG 10000 2025-05-07T18:06:30Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:30Z DEBUG 40 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordMinLength: 2025-05-07T18:06:30Z DEBUG 8 2025-05-07T18:06:30Z DEBUG passwordMinDigits: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinAlphas: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinUppers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinLowers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinSpecials: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMin8bit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinCategories: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordPalindrome: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictCheck: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictPath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordUserAttributes: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordBadWords: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordMaxSequence: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:30Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:30Z DEBUG replication-only 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG passwordMaxFailure: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:30Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-security: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordMaxAge: 2025-05-07T18:06:30Z DEBUG 8640000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:30Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:30Z DEBUG passwordChange: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securePort: 2025-05-07T18:06:30Z DEBUG 636 2025-05-07T18:06:30Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:30Z DEBUG 185 2025-05-07T18:06:30Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordExp: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG day 2025-05-07T18:06:30Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-nagle: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:30Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:30Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:30Z DEBUG uidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:30Z DEBUG gidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:30Z DEBUG dc=example,dc=com 2025-05-07T18:06:30Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:30Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:30Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-counters: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG passwordMinAge: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:30Z DEBUG 209715200 2025-05-07T18:06:30Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:30Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:30Z DEBUG 524288 2025-05-07T18:06:30Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:30Z DEBUG allowed 2025-05-07T18:06:30Z DEBUG nsslapd-config: 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:30Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:30Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:30Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:30Z DEBUG /tmp 2025-05-07T18:06:30Z DEBUG nsslapd-certdir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:30Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:30Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rundir: 2025-05-07T18:06:30Z DEBUG /run/dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:30Z DEBUG 300000 2025-05-07T18:06:30Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-localssf: 2025-05-07T18:06:30Z DEBUG 71 2025-05-07T18:06:30Z DEBUG nsslapd-minssf: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:30Z DEBUG next 2025-05-07T18:06:30Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:30Z DEBUG warn 2025-05-07T18:06:30Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:30Z DEBUG 20971520 2025-05-07T18:06:30Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:30Z DEBUG nolog 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:30Z DEBUG 128 2025-05-07T18:06:30Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:30Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:30Z DEBUG dirsrv-log 2025-05-07T18:06:30Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:30Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:30Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:30Z DEBUG process-safe 2025-05-07T18:06:30Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:30Z DEBUG 30 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordStorageScheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG passwordAdminDN: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:30Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:30Z DEBUG aci: 2025-05-07T18:06:30Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG config 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsslapdConfig 2025-05-07T18:06:30Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:30Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-betype: 2025-05-07T18:06:30Z DEBUG ldbm database 2025-05-07T18:06:30Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:30Z DEBUG cn=schema 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-plugin: 2025-05-07T18:06:30Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:30Z DEBUG 8192 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-port: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-localuser: 2025-05-07T18:06:30Z DEBUG dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordInHistory: 2025-05-07T18:06:30Z DEBUG 6 2025-05-07T18:06:30Z DEBUG passwordUnlock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordGraceLimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordMustChange: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:30Z DEBUG 100000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordWarning: 2025-05-07T18:06:30Z DEBUG 86400 2025-05-07T18:06:30Z DEBUG nsslapd-readonly: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:30Z DEBUG 16 2025-05-07T18:06:30Z DEBUG passwordLockout: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-localhost: 2025-05-07T18:06:30Z DEBUG master.ufreeipa.test 2025-05-07T18:06:30Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:30Z DEBUG 10000 2025-05-07T18:06:30Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:30Z DEBUG 40 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordMinLength: 2025-05-07T18:06:30Z DEBUG 8 2025-05-07T18:06:30Z DEBUG passwordMinDigits: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinAlphas: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinUppers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinLowers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinSpecials: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMin8bit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinCategories: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordPalindrome: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictCheck: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictPath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordUserAttributes: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordBadWords: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordMaxSequence: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:30Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:30Z DEBUG replication-only 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG passwordMaxFailure: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:30Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-security: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordMaxAge: 2025-05-07T18:06:30Z DEBUG 8640000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:30Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:30Z DEBUG passwordChange: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securePort: 2025-05-07T18:06:30Z DEBUG 636 2025-05-07T18:06:30Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:30Z DEBUG 185 2025-05-07T18:06:30Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordExp: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG day 2025-05-07T18:06:30Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-nagle: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:30Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:30Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:30Z DEBUG uidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:30Z DEBUG gidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:30Z DEBUG dc=example,dc=com 2025-05-07T18:06:30Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:30Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:30Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-counters: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG passwordMinAge: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:30Z DEBUG 209715200 2025-05-07T18:06:30Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:30Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:30Z DEBUG 524288 2025-05-07T18:06:30Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:30Z DEBUG allowed 2025-05-07T18:06:30Z DEBUG nsslapd-config: 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:30Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:30Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:30Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:30Z DEBUG /tmp 2025-05-07T18:06:30Z DEBUG nsslapd-certdir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:30Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:30Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rundir: 2025-05-07T18:06:30Z DEBUG /run/dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:30Z DEBUG 300000 2025-05-07T18:06:30Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-localssf: 2025-05-07T18:06:30Z DEBUG 71 2025-05-07T18:06:30Z DEBUG nsslapd-minssf: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:30Z DEBUG next 2025-05-07T18:06:30Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:30Z DEBUG warn 2025-05-07T18:06:30Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:30Z DEBUG 20971520 2025-05-07T18:06:30Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:30Z DEBUG nolog 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:30Z DEBUG 128 2025-05-07T18:06:30Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:30Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:30Z DEBUG dirsrv-log 2025-05-07T18:06:30Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:30Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:30Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:30Z DEBUG process-safe 2025-05-07T18:06:30Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:30Z DEBUG 30 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordStorageScheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG passwordAdminDN: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:30Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:30Z DEBUG aci: 2025-05-07T18:06:30Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:30Z DEBUG only: set nsslapd-enable-upgrade-hash to 'off', current value ['on'] 2025-05-07T18:06:30Z DEBUG only: updated value ['off'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG config 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsslapdConfig 2025-05-07T18:06:30Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:30Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-betype: 2025-05-07T18:06:30Z DEBUG ldbm database 2025-05-07T18:06:30Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:30Z DEBUG cn=schema 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-plugin: 2025-05-07T18:06:30Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:30Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:30Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:30Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:30Z DEBUG 8192 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-port: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-localuser: 2025-05-07T18:06:30Z DEBUG dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordInHistory: 2025-05-07T18:06:30Z DEBUG 6 2025-05-07T18:06:30Z DEBUG passwordUnlock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordGraceLimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG passwordMustChange: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:30Z DEBUG 100000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordWarning: 2025-05-07T18:06:30Z DEBUG 86400 2025-05-07T18:06:30Z DEBUG nsslapd-readonly: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:30Z DEBUG 16 2025-05-07T18:06:30Z DEBUG passwordLockout: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-localhost: 2025-05-07T18:06:30Z DEBUG master.ufreeipa.test 2025-05-07T18:06:30Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:30Z DEBUG 10000 2025-05-07T18:06:30Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:30Z DEBUG 40 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG passwordMinLength: 2025-05-07T18:06:30Z DEBUG 8 2025-05-07T18:06:30Z DEBUG passwordMinDigits: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinAlphas: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinUppers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinLowers: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinSpecials: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMin8bit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMinCategories: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG passwordPalindrome: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictCheck: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordDictPath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordUserAttributes: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordBadWords: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordMaxSequence: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:30Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:30Z DEBUG replication-only 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG passwordMaxFailure: 2025-05-07T18:06:30Z DEBUG 3 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:30Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-security: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordMaxAge: 2025-05-07T18:06:30Z DEBUG 8640000 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:30Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:30Z DEBUG passwordChange: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:30Z DEBUG 256 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securePort: 2025-05-07T18:06:30Z DEBUG 636 2025-05-07T18:06:30Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:30Z DEBUG 185 2025-05-07T18:06:30Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG passwordExp: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG day 2025-05-07T18:06:30Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-nagle: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:30Z DEBUG default 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:30Z DEBUG %FT%TZ 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:30Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:30Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:30Z DEBUG uidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:30Z DEBUG gidNumber 2025-05-07T18:06:30Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:30Z DEBUG dc=example,dc=com 2025-05-07T18:06:30Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:30Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:30Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-counters: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:30Z DEBUG cn=Directory Manager 2025-05-07T18:06:30Z DEBUG passwordMinAge: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:30Z DEBUG 209715200 2025-05-07T18:06:30Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:30Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:30Z DEBUG 524288 2025-05-07T18:06:30Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:30Z DEBUG allowed 2025-05-07T18:06:30Z DEBUG nsslapd-config: 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:30Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:30Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:30Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:30Z DEBUG /tmp 2025-05-07T18:06:30Z DEBUG nsslapd-certdir: 2025-05-07T18:06:30Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:30Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:30Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rundir: 2025-05-07T18:06:30Z DEBUG /run/dirsrv 2025-05-07T18:06:30Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:30Z DEBUG 300000 2025-05-07T18:06:30Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-localssf: 2025-05-07T18:06:30Z DEBUG 71 2025-05-07T18:06:30Z DEBUG nsslapd-minssf: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:30Z DEBUG next 2025-05-07T18:06:30Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:30Z DEBUG warn 2025-05-07T18:06:30Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:30Z DEBUG 20971520 2025-05-07T18:06:30Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:30Z DEBUG nolog 2025-05-07T18:06:30Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:30Z DEBUG 2097152 2025-05-07T18:06:30Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:30Z DEBUG 128 2025-05-07T18:06:30Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:30Z DEBUG -10 2025-05-07T18:06:30Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 2 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:30Z DEBUG 100 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:30Z DEBUG 10 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:30Z DEBUG month 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:30Z DEBUG 5 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:30Z DEBUG week 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:30Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:30Z DEBUG dirsrv-log 2025-05-07T18:06:30Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:30Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:30Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:30Z DEBUG process-safe 2025-05-07T18:06:30Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:30Z DEBUG 3600 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:30Z DEBUG 30 2025-05-07T18:06:30Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:30Z DEBUG 300 2025-05-07T18:06:30Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG passwordStorageScheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG passwordAdminDN: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:30Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:30Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:30Z DEBUG 2025-05-07T18:06:30Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:30Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:30Z DEBUG aci: 2025-05-07T18:06:30Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:30Z DEBUG [(2, 'nsslapd-enable-upgrade-hash', ['off'])] 2025-05-07T18:06:30Z DEBUG Updated 1 2025-05-07T18:06:30Z DEBUG update_entry modlist [(2, 'nsslapd-enable-upgrade-hash', [b'off'])] 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-config.update 0.891 sec 2025-05-07T18:06:30Z DEBUG Parsing update file '/usr/share/ipa/updates/10-db-locks.update' 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=bdb,cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=bdb,cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG bdb 2025-05-07T18:06:30Z DEBUG description: 2025-05-07T18:06:30Z DEBUG The BerkeleyDB config entry (meaningful only if nsslapd-backend-implement is bdb) 2025-05-07T18:06:30Z DEBUG nsslapd-cache-autosize: 2025-05-07T18:06:30Z DEBUG 25 2025-05-07T18:06:30Z DEBUG nsslapd-cache-autosize-split: 2025-05-07T18:06:30Z DEBUG 25 2025-05-07T18:06:30Z DEBUG nsslapd-db-checkpoint-interval: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG nsslapd-db-compactdb-interval: 2025-05-07T18:06:30Z DEBUG 2592000 2025-05-07T18:06:30Z DEBUG nsslapd-db-compactdb-time: 2025-05-07T18:06:30Z DEBUG 23:59 2025-05-07T18:06:30Z DEBUG nsslapd-db-deadlock-policy: 2025-05-07T18:06:30Z DEBUG 9 2025-05-07T18:06:30Z DEBUG nsslapd-db-durable-transaction: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-db-home-directory: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/db 2025-05-07T18:06:30Z DEBUG nsslapd-db-locks: 2025-05-07T18:06:30Z DEBUG 10000 2025-05-07T18:06:30Z DEBUG nsslapd-db-locks-monitoring-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-db-locks-monitoring-pause: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG nsslapd-db-locks-monitoring-threshold: 2025-05-07T18:06:30Z DEBUG 90 2025-05-07T18:06:30Z DEBUG nsslapd-db-logbuf-size: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-db-logdirectory: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/db 2025-05-07T18:06:30Z DEBUG nsslapd-db-private-import-mem: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-db-transaction-batch-max-wait: 2025-05-07T18:06:30Z DEBUG 50 2025-05-07T18:06:30Z DEBUG nsslapd-db-transaction-batch-min-wait: 2025-05-07T18:06:30Z DEBUG 50 2025-05-07T18:06:30Z DEBUG nsslapd-db-transaction-batch-val: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-db-transaction-wait: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-dbcachesize: 2025-05-07T18:06:30Z DEBUG 1610612736 2025-05-07T18:06:30Z DEBUG nsslapd-import-cache-autosize: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG nsslapd-import-cachesize: 2025-05-07T18:06:30Z DEBUG 16777216 2025-05-07T18:06:30Z DEBUG nsslapd-search-bypass-filter-test: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-serial-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG extensibleobject 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG replace: updated value ['50000'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=bdb,cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG bdb 2025-05-07T18:06:30Z DEBUG description: 2025-05-07T18:06:30Z DEBUG The BerkeleyDB config entry (meaningful only if nsslapd-backend-implement is bdb) 2025-05-07T18:06:30Z DEBUG nsslapd-cache-autosize: 2025-05-07T18:06:30Z DEBUG 25 2025-05-07T18:06:30Z DEBUG nsslapd-cache-autosize-split: 2025-05-07T18:06:30Z DEBUG 25 2025-05-07T18:06:30Z DEBUG nsslapd-db-checkpoint-interval: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG nsslapd-db-compactdb-interval: 2025-05-07T18:06:30Z DEBUG 2592000 2025-05-07T18:06:30Z DEBUG nsslapd-db-compactdb-time: 2025-05-07T18:06:30Z DEBUG 23:59 2025-05-07T18:06:30Z DEBUG nsslapd-db-deadlock-policy: 2025-05-07T18:06:30Z DEBUG 9 2025-05-07T18:06:30Z DEBUG nsslapd-db-durable-transaction: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-db-home-directory: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/db 2025-05-07T18:06:30Z DEBUG nsslapd-db-locks: 2025-05-07T18:06:30Z DEBUG 50000 2025-05-07T18:06:30Z DEBUG nsslapd-db-locks-monitoring-enabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-db-locks-monitoring-pause: 2025-05-07T18:06:30Z DEBUG 500 2025-05-07T18:06:30Z DEBUG nsslapd-db-locks-monitoring-threshold: 2025-05-07T18:06:30Z DEBUG 90 2025-05-07T18:06:30Z DEBUG nsslapd-db-logbuf-size: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-db-logdirectory: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/db 2025-05-07T18:06:30Z DEBUG nsslapd-db-private-import-mem: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-db-transaction-batch-max-wait: 2025-05-07T18:06:30Z DEBUG 50 2025-05-07T18:06:30Z DEBUG nsslapd-db-transaction-batch-min-wait: 2025-05-07T18:06:30Z DEBUG 50 2025-05-07T18:06:30Z DEBUG nsslapd-db-transaction-batch-val: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-db-transaction-wait: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-dbcachesize: 2025-05-07T18:06:30Z DEBUG 1610612736 2025-05-07T18:06:30Z DEBUG nsslapd-import-cache-autosize: 2025-05-07T18:06:30Z DEBUG -1 2025-05-07T18:06:30Z DEBUG nsslapd-import-cachesize: 2025-05-07T18:06:30Z DEBUG 16777216 2025-05-07T18:06:30Z DEBUG nsslapd-search-bypass-filter-test: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-serial-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG extensibleobject 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG [(2, 'nsslapd-db-locks', ['50000'])] 2025-05-07T18:06:30Z DEBUG Updated 1 2025-05-07T18:06:30Z DEBUG update_entry modlist [(2, 'nsslapd-db-locks', [b'50000'])] 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG config 2025-05-07T18:06:30Z DEBUG nsslapd-db-home-directory: 2025-05-07T18:06:30Z DEBUG /dev/shm/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsslapd-lookthroughlimit: 2025-05-07T18:06:30Z DEBUG 100000 2025-05-07T18:06:30Z DEBUG nsslapd-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-idlistscanlimit: 2025-05-07T18:06:30Z DEBUG 2147483646 2025-05-07T18:06:30Z DEBUG nsslapd-directory: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/db 2025-05-07T18:06:30Z DEBUG nsslapd-import-cachesize: 2025-05-07T18:06:30Z DEBUG 16777216 2025-05-07T18:06:30Z DEBUG nsslapd-idl-switch: 2025-05-07T18:06:30Z DEBUG new 2025-05-07T18:06:30Z DEBUG nsslapd-search-bypass-filter-test: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-search-use-vlv-index: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-exclude-from-export: 2025-05-07T18:06:30Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2025-05-07T18:06:30Z DEBUG nsslapd-serial-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-subtree-rename-switch: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pagedlookthroughlimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-pagedidlistscanlimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-rangelookthroughlimit: 2025-05-07T18:06:30Z DEBUG 5000 2025-05-07T18:06:30Z DEBUG nsslapd-backend-opt-level: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-backend-implement: 2025-05-07T18:06:30Z DEBUG mdb 2025-05-07T18:06:30Z DEBUG remove: '50000' from nsslapd-db-locks, current value [] 2025-05-07T18:06:30Z DEBUG remove: '50000' not in nsslapd-db-locks 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG config 2025-05-07T18:06:30Z DEBUG nsslapd-db-home-directory: 2025-05-07T18:06:30Z DEBUG /dev/shm/slapd-UFREEIPA-TEST 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsslapd-lookthroughlimit: 2025-05-07T18:06:30Z DEBUG 100000 2025-05-07T18:06:30Z DEBUG nsslapd-mode: 2025-05-07T18:06:30Z DEBUG 600 2025-05-07T18:06:30Z DEBUG nsslapd-idlistscanlimit: 2025-05-07T18:06:30Z DEBUG 2147483646 2025-05-07T18:06:30Z DEBUG nsslapd-directory: 2025-05-07T18:06:30Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/db 2025-05-07T18:06:30Z DEBUG nsslapd-import-cachesize: 2025-05-07T18:06:30Z DEBUG 16777216 2025-05-07T18:06:30Z DEBUG nsslapd-idl-switch: 2025-05-07T18:06:30Z DEBUG new 2025-05-07T18:06:30Z DEBUG nsslapd-search-bypass-filter-test: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-search-use-vlv-index: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-exclude-from-export: 2025-05-07T18:06:30Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2025-05-07T18:06:30Z DEBUG nsslapd-serial-lock: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-subtree-rename-switch: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pagedlookthroughlimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-pagedidlistscanlimit: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG nsslapd-rangelookthroughlimit: 2025-05-07T18:06:30Z DEBUG 5000 2025-05-07T18:06:30Z DEBUG nsslapd-backend-opt-level: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG nsslapd-backend-implement: 2025-05-07T18:06:30Z DEBUG mdb 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-db-locks.update 0.039 sec 2025-05-07T18:06:30Z DEBUG Parsing update file '/usr/share/ipa/updates/10-enable-betxn.update' 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG 7-bit check 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Enforce 7-bit clean attribute values 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG NS7bitAttr 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG NS7bitAttr_Init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libattr-unique-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginarg0: 2025-05-07T18:06:30Z DEBUG uid 2025-05-07T18:06:30Z DEBUG nsslapd-pluginarg1: 2025-05-07T18:06:30Z DEBUG mail 2025-05-07T18:06:30Z DEBUG nsslapd-pluginarg2: 2025-05-07T18:06:30Z DEBUG , 2025-05-07T18:06:30Z DEBUG nsslapd-pluginarg3: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG 7-bit check 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Enforce 7-bit clean attribute values 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG NS7bitAttr 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG NS7bitAttr_Init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libattr-unique-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginarg0: 2025-05-07T18:06:30Z DEBUG uid 2025-05-07T18:06:30Z DEBUG nsslapd-pluginarg1: 2025-05-07T18:06:30Z DEBUG mail 2025-05-07T18:06:30Z DEBUG nsslapd-pluginarg2: 2025-05-07T18:06:30Z DEBUG , 2025-05-07T18:06:30Z DEBUG nsslapd-pluginarg3: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=attribute uniqueness,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG attribute uniqueness 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libattr-unique-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:30Z DEBUG uid 2025-05-07T18:06:30Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG attribute uniqueness 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libattr-unique-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:30Z DEBUG uid 2025-05-07T18:06:30Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG automemberprocessmodifyops: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Auto Membership Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:30Z DEBUG cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Auto Membership plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG Auto Membership 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG automember_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libautomember-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG automemberprocessmodifyops: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Auto Membership Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:30Z DEBUG cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Auto Membership plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG Auto Membership 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG automember_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libautomember-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Linked Attributes 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Linked Attributes plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG Linked Attributes 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG linked_attrs_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG liblinkedattrs-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsContainer 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Linked Attributes 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Linked Attributes plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG Linked Attributes 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG linked_attrs_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG liblinkedattrs-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsContainer 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Managed Entries 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:30Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Managed Entries plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG Managed Entries 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG mep_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libmanagedentries-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsContainer 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Managed Entries 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:30Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Managed Entries plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG Managed Entries 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG mep_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libmanagedentries-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsContainer 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG MemberOf Plugin 2025-05-07T18:06:30Z DEBUG memberofattr: 2025-05-07T18:06:30Z DEBUG memberOf 2025-05-07T18:06:30Z DEBUG memberofgroupattr: 2025-05-07T18:06:30Z DEBUG member 2025-05-07T18:06:30Z DEBUG memberUser 2025-05-07T18:06:30Z DEBUG memberHost 2025-05-07T18:06:30Z DEBUG ipaOwner 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG memberof plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG memberof 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG memberof_postop_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libmemberof-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpostoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpostoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG MemberOf Plugin 2025-05-07T18:06:30Z DEBUG memberofattr: 2025-05-07T18:06:30Z DEBUG memberOf 2025-05-07T18:06:30Z DEBUG memberofgroupattr: 2025-05-07T18:06:30Z DEBUG member 2025-05-07T18:06:30Z DEBUG memberUser 2025-05-07T18:06:30Z DEBUG memberHost 2025-05-07T18:06:30Z DEBUG ipaOwner 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG memberof plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG memberof 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG memberof_postop_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libmemberof-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpostoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Multisupplier Replication Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:30Z DEBUG ldbm database 2025-05-07T18:06:30Z DEBUG AES 2025-05-07T18:06:30Z DEBUG Class of Service 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Multi-supplier Replication Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG replication-multisupplier 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG replication_multisupplier_plugin_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libreplication-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG object 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2025-05-07T18:06:30Z DEBUG only: updated value ['on'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Multisupplier Replication Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:30Z DEBUG ldbm database 2025-05-07T18:06:30Z DEBUG AES 2025-05-07T18:06:30Z DEBUG Class of Service 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Multi-supplier Replication Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG replication-multisupplier 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG replication_multisupplier_plugin_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libreplication-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG object 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=PAM Pass Through Auth,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG PAM Pass Through Auth 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG pam_passthruauth_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libpam-passthru-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginloadglobal: 2025-05-07T18:06:30Z DEBUG true 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG pamConfig 2025-05-07T18:06:30Z DEBUG pamExcludeSuffix: 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG pamFallback: 2025-05-07T18:06:30Z DEBUG FALSE 2025-05-07T18:06:30Z DEBUG pamIDAttr: 2025-05-07T18:06:30Z DEBUG notUsedWithRDNMethod 2025-05-07T18:06:30Z DEBUG pamIDMapMethod: 2025-05-07T18:06:30Z DEBUG RDN 2025-05-07T18:06:30Z DEBUG pamMissingSuffix: 2025-05-07T18:06:30Z DEBUG ALLOW 2025-05-07T18:06:30Z DEBUG pamSecure: 2025-05-07T18:06:30Z DEBUG TRUE 2025-05-07T18:06:30Z DEBUG pamService: 2025-05-07T18:06:30Z DEBUG ldapserver 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpreoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG PAM Pass Through Auth 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG off 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG pam_passthruauth_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libpam-passthru-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpreoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG none 2025-05-07T18:06:30Z DEBUG nsslapd-pluginloadglobal: 2025-05-07T18:06:30Z DEBUG true 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG pamConfig 2025-05-07T18:06:30Z DEBUG pamExcludeSuffix: 2025-05-07T18:06:30Z DEBUG cn=config 2025-05-07T18:06:30Z DEBUG pamFallback: 2025-05-07T18:06:30Z DEBUG FALSE 2025-05-07T18:06:30Z DEBUG pamIDAttr: 2025-05-07T18:06:30Z DEBUG notUsedWithRDNMethod 2025-05-07T18:06:30Z DEBUG pamIDMapMethod: 2025-05-07T18:06:30Z DEBUG RDN 2025-05-07T18:06:30Z DEBUG pamMissingSuffix: 2025-05-07T18:06:30Z DEBUG ALLOW 2025-05-07T18:06:30Z DEBUG pamSecure: 2025-05-07T18:06:30Z DEBUG TRUE 2025-05-07T18:06:30Z DEBUG pamService: 2025-05-07T18:06:30Z DEBUG ldapserver 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG referential integrity postoperation 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG referential integrity plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG referint 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG referint_postop_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libreferint-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpostoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:30Z DEBUG 40 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG referint-logfile: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/referint 2025-05-07T18:06:30Z DEBUG referint-membership-attr: 2025-05-07T18:06:30Z DEBUG member 2025-05-07T18:06:30Z DEBUG uniquemember 2025-05-07T18:06:30Z DEBUG owner 2025-05-07T18:06:30Z DEBUG seeAlso 2025-05-07T18:06:30Z DEBUG referint-update-delay: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpostoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG referential integrity postoperation 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG referential integrity plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG referint 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG referint_postop_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libreferint-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpostoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:30Z DEBUG 40 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG referint-logfile: 2025-05-07T18:06:30Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/referint 2025-05-07T18:06:30Z DEBUG referint-membership-attr: 2025-05-07T18:06:30Z DEBUG member 2025-05-07T18:06:30Z DEBUG uniquemember 2025-05-07T18:06:30Z DEBUG owner 2025-05-07T18:06:30Z DEBUG seeAlso 2025-05-07T18:06:30Z DEBUG referint-update-delay: 2025-05-07T18:06:30Z DEBUG 0 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Roles Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:30Z DEBUG State Change Plugin 2025-05-07T18:06:30Z DEBUG Views 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG roles plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG roles 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG roles_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libroles-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG object 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2025-05-07T18:06:30Z DEBUG only: updated value ['on'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG Roles Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:30Z DEBUG State Change Plugin 2025-05-07T18:06:30Z DEBUG Views 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG roles plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG roles 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG roles_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libroles-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG object 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG State Change Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG state change notification service plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG statechange 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG statechange_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libstatechange-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpostoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpostoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG State Change Plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG state change notification service plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG statechange 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG statechange_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libstatechange-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpostoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=USN,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=USN,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG USN 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG USN (Update Sequence Number) plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG USN 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG usn_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libusn-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG object 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2025-05-07T18:06:30Z DEBUG only: updated value ['on'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=USN,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG USN 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG USN (Update Sequence Number) plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG USN 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG usn_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libusn-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG object 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG IPA MODRDN 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG IPA MODRDN plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG IPA MODRDN 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG ipamodrdn_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libipa_modrdn 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpostoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG Red Hat, Inc. 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 1.0 2025-05-07T18:06:30Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG only: set nsslapd-plugintype to 'betxnpostoperation', current value ['betxnpostoperation'] 2025-05-07T18:06:30Z DEBUG only: updated value ['betxnpostoperation'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG IPA MODRDN 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG IPA MODRDN plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG IPA MODRDN 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG ipamodrdn_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libipa_modrdn 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG betxnpostoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG Red Hat, Inc. 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 1.0 2025-05-07T18:06:30Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:30Z DEBUG 60 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG ipa_pwd_extop 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG IPA Password Extended Operation plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG IPA Password Manager 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG ipapwd_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libipa_pwd_extop 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG extendedop 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG FreeIPA project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG FreeIPA/1.0 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-realmtree: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2025-05-07T18:06:30Z DEBUG only: updated value ['on'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG ipa_pwd_extop 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG IPA Password Extended Operation plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG IPA Password Manager 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG ipapwd_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libipa_pwd_extop 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG extendedop 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG FreeIPA project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG FreeIPA/1.0 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-realmtree: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-enable-betxn.update 0.499 sec 2025-05-07T18:06:30Z DEBUG Parsing update file '/usr/share/ipa/updates/10-ipapwd.update' 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG ipa_pwd_extop 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG IPA Password Extended Operation plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG IPA Password Manager 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG ipapwd_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libipa_pwd_extop 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG extendedop 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG FreeIPA project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG FreeIPA/1.0 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-realmtree: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG add: '49' to nsslapd-pluginprecedence, current value [] 2025-05-07T18:06:30Z DEBUG add: updated value ['49'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG ipa_pwd_extop 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG IPA Password Extended Operation plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG IPA Password Manager 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG ipapwd_init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libipa_pwd_extop 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG extendedop 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG FreeIPA project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG FreeIPA/1.0 2025-05-07T18:06:30Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-realmtree: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:30Z DEBUG 49 2025-05-07T18:06:30Z DEBUG [(2, 'nsslapd-pluginprecedence', ['49'])] 2025-05-07T18:06:30Z DEBUG Updated 1 2025-05-07T18:06:30Z DEBUG update_entry modlist [(2, 'nsslapd-pluginprecedence', [b'49'])] 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-ipapwd.update 0.023 sec 2025-05-07T18:06:30Z DEBUG Parsing update file '/usr/share/ipa/updates/10-rootdse.update' 2025-05-07T18:06:30Z DEBUG Updating existing entry: 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG defaultnamingcontext: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG dataversion: 2025-05-07T18:06:30Z DEBUG 020250507180628020250507180628 2025-05-07T18:06:30Z DEBUG netscapemdsuffix: 2025-05-07T18:06:30Z DEBUG cn=ldap://dc=master,dc=ufreeipa,dc=test:0 2025-05-07T18:06:30Z DEBUG lastusn: 2025-05-07T18:06:30Z DEBUG 448 2025-05-07T18:06:30Z DEBUG ipatopologypluginversion: 2025-05-07T18:06:30Z DEBUG 1.0 2025-05-07T18:06:30Z DEBUG ipatopologyismanaged: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG ipaDomainLevel: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG aci: 2025-05-07T18:06:30Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2025-05-07T18:06:30Z DEBUG add: 'namingContexts' to nsslapd-return-default-opattr, current value [] 2025-05-07T18:06:30Z DEBUG add: updated value ['namingContexts'] 2025-05-07T18:06:30Z DEBUG add: 'supportedControl' to nsslapd-return-default-opattr, current value ['namingContexts'] 2025-05-07T18:06:30Z DEBUG add: updated value ['namingContexts', 'supportedControl'] 2025-05-07T18:06:30Z DEBUG add: 'supportedExtension' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl'] 2025-05-07T18:06:30Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension'] 2025-05-07T18:06:30Z DEBUG add: 'supportedLDAPVersion' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension'] 2025-05-07T18:06:30Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion'] 2025-05-07T18:06:30Z DEBUG add: 'supportedSASLMechanisms' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion'] 2025-05-07T18:06:30Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms'] 2025-05-07T18:06:30Z DEBUG add: 'vendorName' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms'] 2025-05-07T18:06:30Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName'] 2025-05-07T18:06:30Z DEBUG add: 'vendorVersion' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName'] 2025-05-07T18:06:30Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName', 'vendorVersion'] 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG defaultnamingcontext: 2025-05-07T18:06:30Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG dataversion: 2025-05-07T18:06:30Z DEBUG 020250507180628020250507180628 2025-05-07T18:06:30Z DEBUG netscapemdsuffix: 2025-05-07T18:06:30Z DEBUG cn=ldap://dc=master,dc=ufreeipa,dc=test:0 2025-05-07T18:06:30Z DEBUG lastusn: 2025-05-07T18:06:30Z DEBUG 448 2025-05-07T18:06:30Z DEBUG ipatopologypluginversion: 2025-05-07T18:06:30Z DEBUG 1.0 2025-05-07T18:06:30Z DEBUG ipatopologyismanaged: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG ipaDomainLevel: 2025-05-07T18:06:30Z DEBUG 1 2025-05-07T18:06:30Z DEBUG aci: 2025-05-07T18:06:30Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2025-05-07T18:06:30Z DEBUG nsslapd-return-default-opattr: 2025-05-07T18:06:30Z DEBUG namingContexts 2025-05-07T18:06:30Z DEBUG supportedControl 2025-05-07T18:06:30Z DEBUG supportedExtension 2025-05-07T18:06:30Z DEBUG supportedLDAPVersion 2025-05-07T18:06:30Z DEBUG supportedSASLMechanisms 2025-05-07T18:06:30Z DEBUG vendorName 2025-05-07T18:06:30Z DEBUG vendorVersion 2025-05-07T18:06:30Z DEBUG [(2, 'nsslapd-return-default-opattr', ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName', 'vendorVersion'])] 2025-05-07T18:06:30Z DEBUG Updated 1 2025-05-07T18:06:30Z DEBUG update_entry modlist [(2, 'nsslapd-return-default-opattr', [b'namingContexts', b'supportedControl', b'supportedExtension', b'supportedLDAPVersion', b'supportedSASLMechanisms', b'vendorName', b'vendorVersion'])] 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-rootdse.update 0.062 sec 2025-05-07T18:06:30Z DEBUG Parsing update file '/usr/share/ipa/updates/10-selinuxusermap.update' 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=selinux,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=selinux,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsContainer 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG selinux 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=selinux,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsContainer 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG selinux 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=usermap,cn=selinux,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=usermap,cn=selinux,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsContainer 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG usermap 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=usermap,cn=selinux,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsContainer 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG usermap 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-selinuxusermap.update 0.032 sec 2025-05-07T18:06:30Z DEBUG Parsing update file '/usr/share/ipa/updates/10-uniqueness.update' 2025-05-07T18:06:30Z DEBUG Updating existing entry: cn=sudorule name uniqueness,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG sudorule name uniqueness 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Enforce unique attribute values 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libattr-unique-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG preoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:30Z DEBUG cn 2025-05-07T18:06:30Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:30Z DEBUG cn=sudorules,cn=sudo,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG sudorule name uniqueness 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Enforce unique attribute values 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libattr-unique-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG preoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG 389 Project 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 3.1.2 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:30Z DEBUG cn 2025-05-07T18:06:30Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:30Z DEBUG cn=sudorules,cn=sudo,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG [] 2025-05-07T18:06:30Z DEBUG Updated 0 2025-05-07T18:06:30Z DEBUG Done 2025-05-07T18:06:30Z DEBUG New entry: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Initial value 2025-05-07T18:06:30Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG certificate store issuer/serial uniqueness 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Enforce unique attribute values 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libattr-unique-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG preoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:30Z DEBUG ipaCertIssuerSerial 2025-05-07T18:06:30Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:30Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 1.1.0 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG Fedora Project 2025-05-07T18:06:30Z DEBUG --------------------------------------------- 2025-05-07T18:06:30Z DEBUG Final value after applying updates 2025-05-07T18:06:30Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2025-05-07T18:06:30Z DEBUG objectClass: 2025-05-07T18:06:30Z DEBUG top 2025-05-07T18:06:30Z DEBUG nsSlapdPlugin 2025-05-07T18:06:30Z DEBUG extensibleObject 2025-05-07T18:06:30Z DEBUG cn: 2025-05-07T18:06:30Z DEBUG certificate store issuer/serial uniqueness 2025-05-07T18:06:30Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:30Z DEBUG Enforce unique attribute values 2025-05-07T18:06:30Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:30Z DEBUG libattr-unique-plugin 2025-05-07T18:06:30Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:30Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:30Z DEBUG preoperation 2025-05-07T18:06:30Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:30Z DEBUG on 2025-05-07T18:06:30Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:30Z DEBUG ipaCertIssuerSerial 2025-05-07T18:06:30Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:30Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:30Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:30Z DEBUG database 2025-05-07T18:06:30Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:30Z DEBUG NSUniqueAttr 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:30Z DEBUG 1.1.0 2025-05-07T18:06:30Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:30Z DEBUG Fedora Project 2025-05-07T18:06:31Z DEBUG New entry: cn=uid uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG uid uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG uid 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=compat,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-subtree-entries-oc: 2025-05-07T18:06:31Z DEBUG posixAccount 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 1.1.0 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG Fedora Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG uid uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG uid 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=compat,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-subtree-entries-oc: 2025-05-07T18:06:31Z DEBUG posixAccount 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 1.1.0 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG Fedora Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=uid uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG uid uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG uid 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=compat,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-subtree-entries-oc: 2025-05-07T18:06:31Z DEBUG posixAccount 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 1.1.0 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG Fedora Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG add: 'cn=compat,dc=ufreeipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=compat,dc=ufreeipa,dc=test', 'cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test', 'cn=compat,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test', 'cn=compat,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG add: updated value ['cn=compat,dc=ufreeipa,dc=test', 'cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG remove: 'off' from uniqueness-across-all-subtrees, current value ['on'] 2025-05-07T18:06:31Z DEBUG remove: 'off' not in uniqueness-across-all-subtrees 2025-05-07T18:06:31Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2025-05-07T18:06:31Z DEBUG add: updated value ['on'] 2025-05-07T18:06:31Z DEBUG add: 'posixAccount' to uniqueness-subtree-entries-oc, current value ['posixAccount'] 2025-05-07T18:06:31Z DEBUG add: updated value ['posixAccount'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG uid uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG uid 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=compat,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-subtree-entries-oc: 2025-05-07T18:06:31Z DEBUG posixAccount 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 1.1.0 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG Fedora Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG krbPrincipalName uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG 389 Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 3.1.2 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG krbPrincipalName 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2025-05-07T18:06:31Z DEBUG add: updated value ['on'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG krbPrincipalName uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG 389 Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 3.1.2 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG krbPrincipalName 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG krbCanonicalName uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG 389 Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 3.1.2 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG krbCanonicalName 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2025-05-07T18:06:31Z DEBUG add: updated value ['on'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG krbCanonicalName uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG 389 Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 3.1.2 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG krbCanonicalName 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG ipaUniqueID uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG 389 Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 3.1.2 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG ipaUniqueID 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2025-05-07T18:06:31Z DEBUG add: updated value ['on'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG ipaUniqueID uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG 389 Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 3.1.2 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG ipaUniqueID 2025-05-07T18:06:31Z DEBUG uniqueness-exclude-subtrees: 2025-05-07T18:06:31Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG New entry: cn=caacl name uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=caacl name uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG caacl name uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG cn 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG cn=caacls,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 1.1.0 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG Fedora Project 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=caacl name uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG caacl name uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG cn 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG cn=caacls,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 1.1.0 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG Fedora Project 2025-05-07T18:06:31Z DEBUG New entry: cn=ipaSubordinateIdEntry ipaOwner uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=ipaSubordinateIdEntry ipaOwner uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG ipaSubordinateIdEntry ipaOwner uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values of ipaOwner 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG ipaOwner 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG cn=subids,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-subtree-entries-oc: 2025-05-07T18:06:31Z DEBUG ipaSubordinateIdEntry 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 1.1.0 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG Fedora Project 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=ipaSubordinateIdEntry ipaOwner uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG ipaSubordinateIdEntry ipaOwner uniqueness 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Enforce unique attribute values of ipaOwner 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libattr-unique-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr_Init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG preoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-attribute-name: 2025-05-07T18:06:31Z DEBUG ipaOwner 2025-05-07T18:06:31Z DEBUG uniqueness-subtrees: 2025-05-07T18:06:31Z DEBUG cn=subids,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG uniqueness-across-all-subtrees: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG uniqueness-subtree-entries-oc: 2025-05-07T18:06:31Z DEBUG ipaSubordinateIdEntry 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG NSUniqueAttr 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 1.1.0 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG Fedora Project 2025-05-07T18:06:31Z DEBUG Deleting entry cn=certificate store subject uniqueness,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=certificate store subject uniqueness,cn=plugins,cn=config did not exist:no such entry 2025-05-07T18:06:31Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-uniqueness.update 0.409 sec 2025-05-07T18:06:31Z DEBUG Parsing update file '/usr/share/ipa/updates/19-managed-entries.update' 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG Managed Entries 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:31Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Managed Entries plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG Managed Entries 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG mep_init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libmanagedentries-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG betxnpreoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG 389 Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 3.1.2 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG only: set nsslapd-pluginConfigArea to 'cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test', current value ['cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG only: updated value ['cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG Managed Entries 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:31Z DEBUG database 2025-05-07T18:06:31Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:31Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:31Z DEBUG Managed Entries plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:31Z DEBUG Managed Entries 2025-05-07T18:06:31Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:31Z DEBUG mep_init 2025-05-07T18:06:31Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:31Z DEBUG libmanagedentries-plugin 2025-05-07T18:06:31Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:31Z DEBUG betxnpreoperation 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:31Z DEBUG 389 Project 2025-05-07T18:06:31Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:31Z DEBUG 3.1.2 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsSlapdPlugin 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG Managed Entries 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG Managed Entries 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG Templates 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG Templates 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG Definitions 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG Definitions 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG LDAP update duration: /usr/share/ipa/updates/19-managed-entries.update 0.052 sec 2025-05-07T18:06:31Z DEBUG Parsing update file '/usr/share/ipa/updates/20-aci.update' 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=ng,cn=alt,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=ng,cn=alt,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG ng 2025-05-07T18:06:31Z DEBUG add: '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)' to aci, current value [] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=ng,cn=alt,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG ng 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG [(2, 'aci', ['(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG accounts 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG accounts 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG computers 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)' to aci, current value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG computers 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG computers 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)' to aci, current value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG computers 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG add: '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG add: '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG add: '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG add: '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG replicas 2025-05-07T18:06:31Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' from aci, current value [] 2025-05-07T18:06:31Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' not in aci 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG replicas 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG masters 2025-05-07T18:06:31Z DEBUG add: '(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value [] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG masters 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG [(2, 'aci', ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG masters 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG add: '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG masters 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG masters 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG add: '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG masters 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG sysaccounts 2025-05-07T18:06:31Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value [] 2025-05-07T18:06:31Z DEBUG add: updated value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG sysaccounts 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG [(2, 'aci', ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(2, 'aci', [b'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG krbContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG kerberos 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)' to aci, current value [] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG krbContainer 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG kerberos 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG [(2, 'aci', ['(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG add: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', b'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', b'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', b'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', b'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=tasks,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=tasks,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG tasks 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG remove: 'aci: (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from add, current value [] 2025-05-07T18:06:31Z DEBUG remove: 'aci: (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in add 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=tasks,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG tasks 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG mapping tree 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG add: '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: updated value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG mapping tree 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG [(1, 'aci', ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)']), (0, 'aci', ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(1, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)']), (0, 'aci', [b'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG mapping tree 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG mapping tree 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG dc\=ufreeipa\,dc\=test 2025-05-07T18:06:31Z DEBUG nsslapd-backend: 2025-05-07T18:06:31Z DEBUG userRoot 2025-05-07T18:06:31Z DEBUG nsslapd-state: 2025-05-07T18:06:31Z DEBUG backend 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG nsMappingTree 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value [] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value [] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value [] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=dc\=ufreeipa\,dc\=test,cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG dc\=ufreeipa\,dc\=test 2025-05-07T18:06:31Z DEBUG nsslapd-backend: 2025-05-07T18:06:31Z DEBUG userRoot 2025-05-07T18:06:31Z DEBUG nsslapd-state: 2025-05-07T18:06:31Z DEBUG backend 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG nsMappingTree 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=o\=ipaca,cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG o=ipaca 2025-05-07T18:06:31Z DEBUG nsslapd-backend: 2025-05-07T18:06:31Z DEBUG ipaca 2025-05-07T18:06:31Z DEBUG nsslapd-state: 2025-05-07T18:06:31Z DEBUG Backend 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG nsMappingTree 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG o=ipaca 2025-05-07T18:06:31Z DEBUG nsslapd-backend: 2025-05-07T18:06:31Z DEBUG ipaca 2025-05-07T18:06:31Z DEBUG nsslapd-state: 2025-05-07T18:06:31Z DEBUG Backend 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG nsMappingTree 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG nsslapdConfig 2025-05-07T18:06:31Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:31Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-betype: 2025-05-07T18:06:31Z DEBUG ldbm database 2025-05-07T18:06:31Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:31Z DEBUG cn=schema 2025-05-07T18:06:31Z DEBUG cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-plugin: 2025-05-07T18:06:31Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:31Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:31Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:31Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:31Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 10 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:31Z DEBUG 8192 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-port: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:31Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-localuser: 2025-05-07T18:06:31Z DEBUG dirsrv 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG passwordInHistory: 2025-05-07T18:06:31Z DEBUG 6 2025-05-07T18:06:31Z DEBUG passwordUnlock: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG passwordGraceLimit: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG passwordMustChange: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:31Z DEBUG 100000 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG passwordWarning: 2025-05-07T18:06:31Z DEBUG 86400 2025-05-07T18:06:31Z DEBUG nsslapd-readonly: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:31Z DEBUG 16 2025-05-07T18:06:31Z DEBUG passwordLockout: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-localhost: 2025-05-07T18:06:31Z DEBUG master.ufreeipa.test 2025-05-07T18:06:31Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:31Z DEBUG 10000 2025-05-07T18:06:31Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:31Z DEBUG 40 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG passwordMinLength: 2025-05-07T18:06:31Z DEBUG 8 2025-05-07T18:06:31Z DEBUG passwordMinDigits: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinAlphas: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinUppers: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinLowers: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinSpecials: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMin8bit: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinCategories: 2025-05-07T18:06:31Z DEBUG 3 2025-05-07T18:06:31Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:31Z DEBUG 3 2025-05-07T18:06:31Z DEBUG passwordPalindrome: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordDictCheck: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordDictPath: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG passwordUserAttributes: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG passwordBadWords: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG passwordMaxSequence: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:31Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:31Z DEBUG replication-only 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 500 2025-05-07T18:06:31Z DEBUG passwordMaxFailure: 2025-05-07T18:06:31Z DEBUG 3 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:31Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-security: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordMaxAge: 2025-05-07T18:06:31Z DEBUG 8640000 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG week 2025-05-07T18:06:31Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:31Z DEBUG -1 2025-05-07T18:06:31Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:31Z DEBUG -1 2025-05-07T18:06:31Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:31Z DEBUG -1 2025-05-07T18:06:31Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 2 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:31Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:31Z DEBUG passwordChange: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:31Z DEBUG 256 2025-05-07T18:06:31Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:31Z DEBUG 256 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG week 2025-05-07T18:06:31Z DEBUG nsslapd-securePort: 2025-05-07T18:06:31Z DEBUG 636 2025-05-07T18:06:31Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:31Z DEBUG 3600 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:31Z DEBUG 185 2025-05-07T18:06:31Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG passwordExp: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG day 2025-05-07T18:06:31Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:31Z DEBUG 3600 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:31Z DEBUG 3600 2025-05-07T18:06:31Z DEBUG nsslapd-nagle: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:31Z DEBUG default 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:31Z DEBUG %FT%TZ 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:31Z DEBUG default 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:31Z DEBUG %FT%TZ 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:31Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:31Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:31Z DEBUG cn=Directory Manager 2025-05-07T18:06:31Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:31Z DEBUG uidNumber 2025-05-07T18:06:31Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:31Z DEBUG gidNumber 2025-05-07T18:06:31Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:31Z DEBUG dc=example,dc=com 2025-05-07T18:06:31Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:31Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:31Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG nsslapd-counters: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 2 2025-05-07T18:06:31Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:31Z DEBUG cn=Directory Manager 2025-05-07T18:06:31Z DEBUG passwordMinAge: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:31Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:31Z DEBUG 209715200 2025-05-07T18:06:31Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:31Z DEBUG 2097152 2025-05-07T18:06:31Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:31Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:31Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:31Z DEBUG 524288 2025-05-07T18:06:31Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:31Z DEBUG allowed 2025-05-07T18:06:31Z DEBUG nsslapd-config: 2025-05-07T18:06:31Z DEBUG cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:31Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:31Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:31Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:31Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:31Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:31Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:31Z DEBUG /tmp 2025-05-07T18:06:31Z DEBUG nsslapd-certdir: 2025-05-07T18:06:31Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:31Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:31Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:31Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:31Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:31Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-rundir: 2025-05-07T18:06:31Z DEBUG /run/dirsrv 2025-05-07T18:06:31Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:31Z DEBUG 300000 2025-05-07T18:06:31Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-localssf: 2025-05-07T18:06:31Z DEBUG 71 2025-05-07T18:06:31Z DEBUG nsslapd-minssf: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:31Z DEBUG next 2025-05-07T18:06:31Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:31Z DEBUG warn 2025-05-07T18:06:31Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:31Z DEBUG 2097152 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:31Z DEBUG 60 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:31Z DEBUG 20971520 2025-05-07T18:06:31Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:31Z DEBUG nolog 2025-05-07T18:06:31Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:31Z DEBUG 2097152 2025-05-07T18:06:31Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:31Z DEBUG 128 2025-05-07T18:06:31Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:31Z DEBUG -10 2025-05-07T18:06:31Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:31Z DEBUG -10 2025-05-07T18:06:31Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:31Z DEBUG -10 2025-05-07T18:06:31Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:31Z DEBUG -1 2025-05-07T18:06:31Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 2 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG week 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 500 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 10 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG week 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:31Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:31Z DEBUG dirsrv-log 2025-05-07T18:06:31Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:31Z DEBUG none 2025-05-07T18:06:31Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:31Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:31Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:31Z DEBUG process-safe 2025-05-07T18:06:31Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:31Z DEBUG 3600 2025-05-07T18:06:31Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:31Z DEBUG 30 2025-05-07T18:06:31Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:31Z DEBUG 300 2025-05-07T18:06:31Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:31Z DEBUG 300 2025-05-07T18:06:31Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG passwordStorageScheme: 2025-05-07T18:06:31Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:31Z DEBUG passwordAdminDN: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:31Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:31Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=config 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG config 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG extensibleObject 2025-05-07T18:06:31Z DEBUG nsslapdConfig 2025-05-07T18:06:31Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:31Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-betype: 2025-05-07T18:06:31Z DEBUG ldbm database 2025-05-07T18:06:31Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:31Z DEBUG cn=schema 2025-05-07T18:06:31Z DEBUG cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-plugin: 2025-05-07T18:06:31Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:31Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:31Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:31Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:31Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:31Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:31Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 10 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:31Z DEBUG 8192 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-port: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:31Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-localuser: 2025-05-07T18:06:31Z DEBUG dirsrv 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG passwordInHistory: 2025-05-07T18:06:31Z DEBUG 6 2025-05-07T18:06:31Z DEBUG passwordUnlock: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG passwordGraceLimit: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG passwordMustChange: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:31Z DEBUG 100000 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG passwordWarning: 2025-05-07T18:06:31Z DEBUG 86400 2025-05-07T18:06:31Z DEBUG nsslapd-readonly: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:31Z DEBUG 16 2025-05-07T18:06:31Z DEBUG passwordLockout: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-localhost: 2025-05-07T18:06:31Z DEBUG master.ufreeipa.test 2025-05-07T18:06:31Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:31Z DEBUG 10000 2025-05-07T18:06:31Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:31Z DEBUG 40 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG passwordMinLength: 2025-05-07T18:06:31Z DEBUG 8 2025-05-07T18:06:31Z DEBUG passwordMinDigits: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinAlphas: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinUppers: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinLowers: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinSpecials: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMin8bit: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMinCategories: 2025-05-07T18:06:31Z DEBUG 3 2025-05-07T18:06:31Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:31Z DEBUG 3 2025-05-07T18:06:31Z DEBUG passwordPalindrome: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordDictCheck: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordDictPath: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG passwordUserAttributes: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG passwordBadWords: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG passwordMaxSequence: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:31Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:31Z DEBUG replication-only 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 500 2025-05-07T18:06:31Z DEBUG passwordMaxFailure: 2025-05-07T18:06:31Z DEBUG 3 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:31Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-security: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordMaxAge: 2025-05-07T18:06:31Z DEBUG 8640000 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG week 2025-05-07T18:06:31Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:31Z DEBUG -1 2025-05-07T18:06:31Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:31Z DEBUG -1 2025-05-07T18:06:31Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:31Z DEBUG -1 2025-05-07T18:06:31Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 2 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:31Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:31Z DEBUG passwordChange: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:31Z DEBUG 256 2025-05-07T18:06:31Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:31Z DEBUG 256 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG week 2025-05-07T18:06:31Z DEBUG nsslapd-securePort: 2025-05-07T18:06:31Z DEBUG 636 2025-05-07T18:06:31Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:31Z DEBUG 3600 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:31Z DEBUG 185 2025-05-07T18:06:31Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG passwordExp: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG day 2025-05-07T18:06:31Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:31Z DEBUG 3600 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:31Z DEBUG 3600 2025-05-07T18:06:31Z DEBUG nsslapd-nagle: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:31Z DEBUG default 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:31Z DEBUG %FT%TZ 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:31Z DEBUG default 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:31Z DEBUG %FT%TZ 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:31Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:31Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:31Z DEBUG cn=Directory Manager 2025-05-07T18:06:31Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:31Z DEBUG uidNumber 2025-05-07T18:06:31Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:31Z DEBUG gidNumber 2025-05-07T18:06:31Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:31Z DEBUG dc=example,dc=com 2025-05-07T18:06:31Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:31Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:31Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG nsslapd-counters: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 2 2025-05-07T18:06:31Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:31Z DEBUG cn=Directory Manager 2025-05-07T18:06:31Z DEBUG passwordMinAge: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:31Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:31Z DEBUG 209715200 2025-05-07T18:06:31Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:31Z DEBUG 2097152 2025-05-07T18:06:31Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:31Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:31Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:31Z DEBUG 524288 2025-05-07T18:06:31Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:31Z DEBUG allowed 2025-05-07T18:06:31Z DEBUG nsslapd-config: 2025-05-07T18:06:31Z DEBUG cn=config 2025-05-07T18:06:31Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:31Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:31Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:31Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:31Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:31Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:31Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:31Z DEBUG /tmp 2025-05-07T18:06:31Z DEBUG nsslapd-certdir: 2025-05-07T18:06:31Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:31Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:31Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:31Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:31Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:31Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-rundir: 2025-05-07T18:06:31Z DEBUG /run/dirsrv 2025-05-07T18:06:31Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:31Z DEBUG 300000 2025-05-07T18:06:31Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-localssf: 2025-05-07T18:06:31Z DEBUG 71 2025-05-07T18:06:31Z DEBUG nsslapd-minssf: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:31Z DEBUG next 2025-05-07T18:06:31Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:31Z DEBUG warn 2025-05-07T18:06:31Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:31Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:31Z DEBUG 2097152 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:31Z DEBUG 60 2025-05-07T18:06:31Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:31Z DEBUG 20971520 2025-05-07T18:06:31Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:31Z DEBUG nolog 2025-05-07T18:06:31Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:31Z DEBUG 2097152 2025-05-07T18:06:31Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:31Z DEBUG 128 2025-05-07T18:06:31Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:31Z DEBUG -10 2025-05-07T18:06:31Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:31Z DEBUG -10 2025-05-07T18:06:31Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:31Z DEBUG -10 2025-05-07T18:06:31Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:31Z DEBUG -1 2025-05-07T18:06:31Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 2 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG week 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:31Z DEBUG 600 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:31Z DEBUG 0 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:31Z DEBUG 500 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:31Z DEBUG 100 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:31Z DEBUG 1 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:31Z DEBUG 10 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:31Z DEBUG month 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:31Z DEBUG 5 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:31Z DEBUG week 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:31Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:31Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:31Z DEBUG dirsrv-log 2025-05-07T18:06:31Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:31Z DEBUG none 2025-05-07T18:06:31Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:31Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:31Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:31Z DEBUG process-safe 2025-05-07T18:06:31Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:31Z DEBUG 3600 2025-05-07T18:06:31Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:31Z DEBUG 30 2025-05-07T18:06:31Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:31Z DEBUG 300 2025-05-07T18:06:31Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:31Z DEBUG 300 2025-05-07T18:06:31Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG passwordStorageScheme: 2025-05-07T18:06:31Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:31Z DEBUG passwordAdminDN: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:31Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:31Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:31Z DEBUG on 2025-05-07T18:06:31Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:31Z DEBUG off 2025-05-07T18:06:31Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:31Z DEBUG 2025-05-07T18:06:31Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:31Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=ufreeipa,dc=test")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=ufreeipa,dc=test")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=ufreeipa,dc=test")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=ufreeipa,dc=test")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG hbac 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG hbac 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=sudo,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=sudo,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG sudo 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=sudo,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG sudo 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG accounts 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG accounts 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG domain 2025-05-07T18:06:31Z DEBUG pilotObject 2025-05-07T18:06:31Z DEBUG dc: 2025-05-07T18:06:31Z DEBUG ufreeipa 2025-05-07T18:06:31Z DEBUG info: 2025-05-07T18:06:31Z DEBUG IPA V2.0 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:31Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:31Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG groups 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)' from aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)' not in aci 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)' to aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG groups 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG hostgroups 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)' from aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG remove: '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)' not in aci 2025-05-07T18:06:31Z DEBUG add: '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)' to aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG hostgroups 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2025-05-07T18:06:31Z DEBUG [] 2025-05-07T18:06:31Z DEBUG Updated 0 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG services 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2025-05-07T18:06:31Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:31Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG services 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG [(0, 'aci', ['(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', b'(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Done 2025-05-07T18:06:31Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Initial value 2025-05-07T18:06:31Z DEBUG dn: cn=ranges,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG ranges 2025-05-07T18:06:31Z DEBUG add: '(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)' to aci, current value [] 2025-05-07T18:06:31Z DEBUG add: updated value ['(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:31Z DEBUG --------------------------------------------- 2025-05-07T18:06:31Z DEBUG Final value after applying updates 2025-05-07T18:06:31Z DEBUG dn: cn=ranges,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:31Z DEBUG objectClass: 2025-05-07T18:06:31Z DEBUG top 2025-05-07T18:06:31Z DEBUG nsContainer 2025-05-07T18:06:31Z DEBUG cn: 2025-05-07T18:06:31Z DEBUG ranges 2025-05-07T18:06:31Z DEBUG aci: 2025-05-07T18:06:31Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:31Z DEBUG [(2, 'aci', ['(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:31Z DEBUG Updated 1 2025-05-07T18:06:31Z DEBUG update_entry modlist [(2, 'aci', [b'(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG sysaccounts 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: updated value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG sysaccounts 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:32Z DEBUG Updated 1 2025-05-07T18:06:32Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG etc 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG add: '(target = "ldap:///cn=replication,cn=etc,dc=ufreeipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: updated value ['(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=replication,cn=etc,dc=ufreeipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG etc 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=replication,cn=etc,dc=ufreeipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=replication,cn=etc,dc=ufreeipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:32Z DEBUG Updated 1 2025-05-07T18:06:32Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=replication,cn=etc,dc=ufreeipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ipa 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ipa 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:32Z DEBUG Updated 1 2025-05-07T18:06:32Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', b'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ipa 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ipa 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:32Z DEBUG Updated 1 2025-05-07T18:06:32Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', b'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', b'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: krbPrincipalName=WELLKNOWN/ANONYMOUS@UFREEIPA.TEST,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@UFREEIPA.TEST,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbprincipal 2025-05-07T18:06:32Z DEBUG krbprincipalaux 2025-05-07T18:06:32Z DEBUG krbTicketPolicyAux 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ipaAllowedOperations 2025-05-07T18:06:32Z DEBUG krbPrincipalName: 2025-05-07T18:06:32Z DEBUG WELLKNOWN/ANONYMOUS@UFREEIPA.TEST 2025-05-07T18:06:32Z DEBUG krbCanonicalName: 2025-05-07T18:06:32Z DEBUG WELLKNOWN/ANONYMOUS@UFREEIPA.TEST 2025-05-07T18:06:32Z DEBUG krbLastPwdChange: 2025-05-07T18:06:32Z DEBUG 20250507180232Z 2025-05-07T18:06:32Z DEBUG krbPrincipalKey: 2025-05-07T18:06:32Z DEBUG XXXXXXXX 2025-05-07T18:06:32Z DEBUG krbExtraData: 2025-05-07T18:06:32Z DEBUG AAI4oBtocm9vdC9hZG1pbkBVRlJFRUlQQS5URVNUAA== 2025-05-07T18:06:32Z DEBUG ipaAllowedToPerform;read_keys: 2025-05-07T18:06:32Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:32Z DEBUG addifexist: 'ipaAllowedOperations' to objectclass, current value ['krbprincipal', 'krbprincipalaux', 'krbTicketPolicyAux', 'top', 'ipaAllowedOperations'] 2025-05-07T18:06:32Z DEBUG addifexist: set objectclass to ['krbprincipal', 'krbprincipalaux', 'krbTicketPolicyAux', 'top', 'ipaAllowedOperations', 'ipaAllowedOperations'] 2025-05-07T18:06:32Z DEBUG addifexist: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2025-05-07T18:06:32Z DEBUG addifexist: set aci to ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2025-05-07T18:06:32Z DEBUG addifexist: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test' to ipaAllowedToPerform;read_keys, current value ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:32Z DEBUG addifexist: set ipaAllowedToPerform;read_keys to ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@UFREEIPA.TEST,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbprincipal 2025-05-07T18:06:32Z DEBUG krbprincipalaux 2025-05-07T18:06:32Z DEBUG krbTicketPolicyAux 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ipaAllowedOperations 2025-05-07T18:06:32Z DEBUG ipaAllowedOperations 2025-05-07T18:06:32Z DEBUG krbPrincipalName: 2025-05-07T18:06:32Z DEBUG WELLKNOWN/ANONYMOUS@UFREEIPA.TEST 2025-05-07T18:06:32Z DEBUG krbCanonicalName: 2025-05-07T18:06:32Z DEBUG WELLKNOWN/ANONYMOUS@UFREEIPA.TEST 2025-05-07T18:06:32Z DEBUG krbLastPwdChange: 2025-05-07T18:06:32Z DEBUG 20250507180232Z 2025-05-07T18:06:32Z DEBUG krbPrincipalKey: 2025-05-07T18:06:32Z DEBUG XXXXXXXX 2025-05-07T18:06:32Z DEBUG krbExtraData: 2025-05-07T18:06:32Z DEBUG AAI4oBtocm9vdC9hZG1pbkBVRlJFRUlQQS5URVNUAA== 2025-05-07T18:06:32Z DEBUG ipaAllowedToPerform;read_keys: 2025-05-07T18:06:32Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:32Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Posix IDs 2025-05-07T18:06:32Z DEBUG dnaExcludeScope: 2025-05-07T18:06:32Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG dnaFilter: 2025-05-07T18:06:32Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2025-05-07T18:06:32Z DEBUG dnaMagicRegen: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG dnaMaxValue: 2025-05-07T18:06:32Z DEBUG 63999999 2025-05-07T18:06:32Z DEBUG dnaNextValue: 2025-05-07T18:06:32Z DEBUG 63800000 2025-05-07T18:06:32Z DEBUG dnaScope: 2025-05-07T18:06:32Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG dnaSharedCfgDN: 2025-05-07T18:06:32Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG dnaThreshold: 2025-05-07T18:06:32Z DEBUG 500 2025-05-07T18:06:32Z DEBUG dnaType: 2025-05-07T18:06:32Z DEBUG uidNumber 2025-05-07T18:06:32Z DEBUG gidNumber 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG remove: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG remove: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:32Z DEBUG add: '(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Posix IDs 2025-05-07T18:06:32Z DEBUG dnaExcludeScope: 2025-05-07T18:06:32Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG dnaFilter: 2025-05-07T18:06:32Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2025-05-07T18:06:32Z DEBUG dnaMagicRegen: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG dnaMaxValue: 2025-05-07T18:06:32Z DEBUG 63999999 2025-05-07T18:06:32Z DEBUG dnaNextValue: 2025-05-07T18:06:32Z DEBUG 63800000 2025-05-07T18:06:32Z DEBUG dnaScope: 2025-05-07T18:06:32Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG dnaSharedCfgDN: 2025-05-07T18:06:32Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG dnaThreshold: 2025-05-07T18:06:32Z DEBUG 500 2025-05-07T18:06:32Z DEBUG dnaType: 2025-05-07T18:06:32Z DEBUG uidNumber 2025-05-07T18:06:32Z DEBUG gidNumber 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG userRoot 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG nsBackendInstance 2025-05-07T18:06:32Z DEBUG nsslapd-suffix: 2025-05-07T18:06:32Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG nsslapd-cachesize: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG nsslapd-cachememsize: 2025-05-07T18:06:32Z DEBUG 512000 2025-05-07T18:06:32Z DEBUG nsslapd-readonly: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-require-index: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-require-internalop-index: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-dncachememsize: 2025-05-07T18:06:32Z DEBUG 16777216 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG remove: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG remove: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:32Z DEBUG add: '(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG add: updated value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG userRoot 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG nsBackendInstance 2025-05-07T18:06:32Z DEBUG nsslapd-suffix: 2025-05-07T18:06:32Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG nsslapd-cachesize: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG nsslapd-cachememsize: 2025-05-07T18:06:32Z DEBUG 512000 2025-05-07T18:06:32Z DEBUG nsslapd-readonly: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-require-index: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-require-internalop-index: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-dncachememsize: 2025-05-07T18:06:32Z DEBUG 16777216 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-aci.update 0.793 sec 2025-05-07T18:06:32Z DEBUG Parsing update file '/usr/share/ipa/updates/20-autobind.update' 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=auto_bind,cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=auto_bind,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG auto_bind 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=auto_bind,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG auto_bind 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG config 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG nsslapdConfig 2025-05-07T18:06:32Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:32Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-betype: 2025-05-07T18:06:32Z DEBUG ldbm database 2025-05-07T18:06:32Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:32Z DEBUG cn=schema 2025-05-07T18:06:32Z DEBUG cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-plugin: 2025-05-07T18:06:32Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:32Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:32Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:32Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:32Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 10 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:32Z DEBUG 8192 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-port: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:32Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-localuser: 2025-05-07T18:06:32Z DEBUG dirsrv 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG passwordInHistory: 2025-05-07T18:06:32Z DEBUG 6 2025-05-07T18:06:32Z DEBUG passwordUnlock: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG passwordGraceLimit: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG passwordMustChange: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:32Z DEBUG 100000 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG passwordWarning: 2025-05-07T18:06:32Z DEBUG 86400 2025-05-07T18:06:32Z DEBUG nsslapd-readonly: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:32Z DEBUG 16 2025-05-07T18:06:32Z DEBUG passwordLockout: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-localhost: 2025-05-07T18:06:32Z DEBUG master.ufreeipa.test 2025-05-07T18:06:32Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:32Z DEBUG 10000 2025-05-07T18:06:32Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:32Z DEBUG 40 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG passwordMinLength: 2025-05-07T18:06:32Z DEBUG 8 2025-05-07T18:06:32Z DEBUG passwordMinDigits: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinAlphas: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinUppers: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinLowers: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinSpecials: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMin8bit: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinCategories: 2025-05-07T18:06:32Z DEBUG 3 2025-05-07T18:06:32Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:32Z DEBUG 3 2025-05-07T18:06:32Z DEBUG passwordPalindrome: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordDictCheck: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordDictPath: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG passwordUserAttributes: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG passwordBadWords: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG passwordMaxSequence: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:32Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:32Z DEBUG replication-only 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 500 2025-05-07T18:06:32Z DEBUG passwordMaxFailure: 2025-05-07T18:06:32Z DEBUG 3 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:32Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-security: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordMaxAge: 2025-05-07T18:06:32Z DEBUG 8640000 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG week 2025-05-07T18:06:32Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 2 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:32Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:32Z DEBUG passwordChange: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:32Z DEBUG 256 2025-05-07T18:06:32Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:32Z DEBUG 256 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG week 2025-05-07T18:06:32Z DEBUG nsslapd-securePort: 2025-05-07T18:06:32Z DEBUG 636 2025-05-07T18:06:32Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:32Z DEBUG 3600 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:32Z DEBUG 185 2025-05-07T18:06:32Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG passwordExp: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG day 2025-05-07T18:06:32Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:32Z DEBUG 3600 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:32Z DEBUG 3600 2025-05-07T18:06:32Z DEBUG nsslapd-nagle: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:32Z DEBUG default 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:32Z DEBUG %FT%TZ 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:32Z DEBUG default 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:32Z DEBUG %FT%TZ 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:32Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:32Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:32Z DEBUG cn=Directory Manager 2025-05-07T18:06:32Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:32Z DEBUG uidNumber 2025-05-07T18:06:32Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:32Z DEBUG gidNumber 2025-05-07T18:06:32Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:32Z DEBUG dc=example,dc=com 2025-05-07T18:06:32Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:32Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:32Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG nsslapd-counters: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 2 2025-05-07T18:06:32Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:32Z DEBUG cn=Directory Manager 2025-05-07T18:06:32Z DEBUG passwordMinAge: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:32Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:32Z DEBUG 209715200 2025-05-07T18:06:32Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:32Z DEBUG 2097152 2025-05-07T18:06:32Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:32Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:32Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:32Z DEBUG 524288 2025-05-07T18:06:32Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:32Z DEBUG allowed 2025-05-07T18:06:32Z DEBUG nsslapd-config: 2025-05-07T18:06:32Z DEBUG cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:32Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:32Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:32Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:32Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:32Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:32Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:32Z DEBUG /tmp 2025-05-07T18:06:32Z DEBUG nsslapd-certdir: 2025-05-07T18:06:32Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:32Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:32Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:32Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:32Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:32Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-rundir: 2025-05-07T18:06:32Z DEBUG /run/dirsrv 2025-05-07T18:06:32Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:32Z DEBUG 300000 2025-05-07T18:06:32Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-localssf: 2025-05-07T18:06:32Z DEBUG 71 2025-05-07T18:06:32Z DEBUG nsslapd-minssf: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:32Z DEBUG next 2025-05-07T18:06:32Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:32Z DEBUG warn 2025-05-07T18:06:32Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:32Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:32Z DEBUG 2097152 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:32Z DEBUG 60 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:32Z DEBUG 20971520 2025-05-07T18:06:32Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:32Z DEBUG nolog 2025-05-07T18:06:32Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:32Z DEBUG 2097152 2025-05-07T18:06:32Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:32Z DEBUG 128 2025-05-07T18:06:32Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:32Z DEBUG -10 2025-05-07T18:06:32Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:32Z DEBUG -10 2025-05-07T18:06:32Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:32Z DEBUG -10 2025-05-07T18:06:32Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 2 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG week 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 500 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 10 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG week 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:32Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:32Z DEBUG dirsrv-log 2025-05-07T18:06:32Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:32Z DEBUG none 2025-05-07T18:06:32Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:32Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:32Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:32Z DEBUG process-safe 2025-05-07T18:06:32Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:32Z DEBUG 3600 2025-05-07T18:06:32Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:32Z DEBUG 30 2025-05-07T18:06:32Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:32Z DEBUG 300 2025-05-07T18:06:32Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:32Z DEBUG 300 2025-05-07T18:06:32Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG passwordStorageScheme: 2025-05-07T18:06:32Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:32Z DEBUG passwordAdminDN: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:32Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:32Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:32Z DEBUG only: set nsslapd-ldapimaptoentries to 'on', current value ['off'] 2025-05-07T18:06:32Z DEBUG only: updated value ['on'] 2025-05-07T18:06:32Z DEBUG only: set nsslapd-ldapientrysearchbase to 'cn=auto_bind,cn=config', current value ['dc=example,dc=com'] 2025-05-07T18:06:32Z DEBUG only: updated value ['cn=auto_bind,cn=config'] 2025-05-07T18:06:32Z DEBUG only: set nsslapd-ldapidnmappingbase to 'cn=auto_bind,cn=config', current value ['cn=auto_bind,cn=config'] 2025-05-07T18:06:32Z DEBUG only: updated value ['cn=auto_bind,cn=config'] 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG config 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG nsslapdConfig 2025-05-07T18:06:32Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:32Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-betype: 2025-05-07T18:06:32Z DEBUG ldbm database 2025-05-07T18:06:32Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:32Z DEBUG cn=schema 2025-05-07T18:06:32Z DEBUG cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-plugin: 2025-05-07T18:06:32Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:32Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:32Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:32Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:32Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:32Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:32Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 10 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:32Z DEBUG 8192 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-port: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:32Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-localuser: 2025-05-07T18:06:32Z DEBUG dirsrv 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG passwordInHistory: 2025-05-07T18:06:32Z DEBUG 6 2025-05-07T18:06:32Z DEBUG passwordUnlock: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG passwordGraceLimit: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG passwordMustChange: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:32Z DEBUG 100000 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG passwordWarning: 2025-05-07T18:06:32Z DEBUG 86400 2025-05-07T18:06:32Z DEBUG nsslapd-readonly: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:32Z DEBUG 16 2025-05-07T18:06:32Z DEBUG passwordLockout: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-localhost: 2025-05-07T18:06:32Z DEBUG master.ufreeipa.test 2025-05-07T18:06:32Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:32Z DEBUG 10000 2025-05-07T18:06:32Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:32Z DEBUG 40 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG passwordMinLength: 2025-05-07T18:06:32Z DEBUG 8 2025-05-07T18:06:32Z DEBUG passwordMinDigits: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinAlphas: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinUppers: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinLowers: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinSpecials: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMin8bit: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMinCategories: 2025-05-07T18:06:32Z DEBUG 3 2025-05-07T18:06:32Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:32Z DEBUG 3 2025-05-07T18:06:32Z DEBUG passwordPalindrome: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordDictCheck: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordDictPath: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG passwordUserAttributes: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG passwordBadWords: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG passwordMaxSequence: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:32Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:32Z DEBUG replication-only 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 500 2025-05-07T18:06:32Z DEBUG passwordMaxFailure: 2025-05-07T18:06:32Z DEBUG 3 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:32Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-security: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordMaxAge: 2025-05-07T18:06:32Z DEBUG 8640000 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG week 2025-05-07T18:06:32Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 2 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:32Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:32Z DEBUG passwordChange: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:32Z DEBUG 256 2025-05-07T18:06:32Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:32Z DEBUG 256 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG week 2025-05-07T18:06:32Z DEBUG nsslapd-securePort: 2025-05-07T18:06:32Z DEBUG 636 2025-05-07T18:06:32Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:32Z DEBUG 3600 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:32Z DEBUG 185 2025-05-07T18:06:32Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG passwordExp: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG day 2025-05-07T18:06:32Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:32Z DEBUG 3600 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:32Z DEBUG 3600 2025-05-07T18:06:32Z DEBUG nsslapd-nagle: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:32Z DEBUG default 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:32Z DEBUG %FT%TZ 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:32Z DEBUG default 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:32Z DEBUG %FT%TZ 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:32Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:32Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:32Z DEBUG cn=Directory Manager 2025-05-07T18:06:32Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:32Z DEBUG uidNumber 2025-05-07T18:06:32Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:32Z DEBUG gidNumber 2025-05-07T18:06:32Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:32Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:32Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:32Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG nsslapd-counters: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 2 2025-05-07T18:06:32Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:32Z DEBUG cn=Directory Manager 2025-05-07T18:06:32Z DEBUG passwordMinAge: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:32Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:32Z DEBUG 209715200 2025-05-07T18:06:32Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:32Z DEBUG 2097152 2025-05-07T18:06:32Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:32Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:32Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:32Z DEBUG 524288 2025-05-07T18:06:32Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:32Z DEBUG allowed 2025-05-07T18:06:32Z DEBUG nsslapd-config: 2025-05-07T18:06:32Z DEBUG cn=config 2025-05-07T18:06:32Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:32Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:32Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:32Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:32Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:32Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:32Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:32Z DEBUG /tmp 2025-05-07T18:06:32Z DEBUG nsslapd-certdir: 2025-05-07T18:06:32Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:32Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:32Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:32Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:32Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:32Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-rundir: 2025-05-07T18:06:32Z DEBUG /run/dirsrv 2025-05-07T18:06:32Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:32Z DEBUG 300000 2025-05-07T18:06:32Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-localssf: 2025-05-07T18:06:32Z DEBUG 71 2025-05-07T18:06:32Z DEBUG nsslapd-minssf: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:32Z DEBUG next 2025-05-07T18:06:32Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:32Z DEBUG warn 2025-05-07T18:06:32Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:32Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:32Z DEBUG 2097152 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:32Z DEBUG 60 2025-05-07T18:06:32Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:32Z DEBUG 20971520 2025-05-07T18:06:32Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:32Z DEBUG nolog 2025-05-07T18:06:32Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:32Z DEBUG 2097152 2025-05-07T18:06:32Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:32Z DEBUG 128 2025-05-07T18:06:32Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:32Z DEBUG -10 2025-05-07T18:06:32Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:32Z DEBUG -10 2025-05-07T18:06:32Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:32Z DEBUG -10 2025-05-07T18:06:32Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:32Z DEBUG -1 2025-05-07T18:06:32Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 2 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG week 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:32Z DEBUG 600 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:32Z DEBUG 500 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:32Z DEBUG 100 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:32Z DEBUG 1 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:32Z DEBUG 10 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:32Z DEBUG month 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:32Z DEBUG 5 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:32Z DEBUG week 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:32Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:32Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:32Z DEBUG dirsrv-log 2025-05-07T18:06:32Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:32Z DEBUG none 2025-05-07T18:06:32Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:32Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:32Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:32Z DEBUG process-safe 2025-05-07T18:06:32Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:32Z DEBUG 3600 2025-05-07T18:06:32Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:32Z DEBUG 30 2025-05-07T18:06:32Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:32Z DEBUG 300 2025-05-07T18:06:32Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:32Z DEBUG 300 2025-05-07T18:06:32Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG passwordStorageScheme: 2025-05-07T18:06:32Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:32Z DEBUG passwordAdminDN: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:32Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:32Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:32Z DEBUG off 2025-05-07T18:06:32Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:32Z DEBUG 2025-05-07T18:06:32Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:32Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:32Z DEBUG aci: 2025-05-07T18:06:32Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:32Z DEBUG [(2, 'nsslapd-ldapientrysearchbase', ['cn=auto_bind,cn=config']), (2, 'nsslapd-ldapimaptoentries', ['on'])] 2025-05-07T18:06:32Z DEBUG Updated 1 2025-05-07T18:06:32Z DEBUG update_entry modlist [(2, 'nsslapd-ldapientrysearchbase', [b'cn=auto_bind,cn=config']), (2, 'nsslapd-ldapimaptoentries', [b'on'])] 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Deleting entry cn=root-autobind,cn=config 2025-05-07T18:06:32Z DEBUG cn=root-autobind,cn=config did not exist:no such entry 2025-05-07T18:06:32Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-autobind.update 0.085 sec 2025-05-07T18:06:32Z DEBUG Parsing update file '/usr/share/ipa/updates/20-default_password_policy.update' 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbPwdPolicy 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Host Password Policy 2025-05-07T18:06:32Z DEBUG krbMinPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinDiffChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdHistoryLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbMaxPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMaxFailure: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdFailureCountInterval: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdLockoutDuration: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbPwdPolicy 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Host Password Policy 2025-05-07T18:06:32Z DEBUG krbMinPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinDiffChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdHistoryLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbMaxPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMaxFailure: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdFailureCountInterval: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdLockoutDuration: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Service Password Policy,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbPwdPolicy 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Service Password Policy 2025-05-07T18:06:32Z DEBUG krbMinPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinDiffChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdHistoryLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbMaxPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMaxFailure: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdFailureCountInterval: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdLockoutDuration: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbPwdPolicy 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Service Password Policy 2025-05-07T18:06:32Z DEBUG krbMinPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinDiffChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdHistoryLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbMaxPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMaxFailure: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdFailureCountInterval: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdLockoutDuration: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG New entry: cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Kerberos Service Password Policy 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Kerberos Service Password Policy 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbPwdPolicy 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Kerberos Service Password Policy 2025-05-07T18:06:32Z DEBUG krbMinPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinDiffChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdHistoryLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbMaxPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMaxFailure: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdFailureCountInterval: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdLockoutDuration: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbPwdPolicy 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Kerberos Service Password Policy 2025-05-07T18:06:32Z DEBUG krbMinPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinDiffChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdHistoryLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbMaxPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMaxFailure: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdFailureCountInterval: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdLockoutDuration: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG New entry: cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbPwdPolicy 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default System Accounts Password Policy 2025-05-07T18:06:32Z DEBUG krbMinPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinDiffChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinLength: 2025-05-07T18:06:32Z DEBUG 8 2025-05-07T18:06:32Z DEBUG krbPwdHistoryLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbMaxPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMaxFailure: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdFailureCountInterval: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdLockoutDuration: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG krbPwdPolicy 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default System Accounts Password Policy 2025-05-07T18:06:32Z DEBUG krbMinPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinDiffChars: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMinLength: 2025-05-07T18:06:32Z DEBUG 8 2025-05-07T18:06:32Z DEBUG krbPwdHistoryLength: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbMaxPwdLife: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdMaxFailure: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdFailureCountInterval: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG krbPwdLockoutDuration: 2025-05-07T18:06:32Z DEBUG 0 2025-05-07T18:06:32Z DEBUG New entry: cn=cosTemplates,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG cosTemplates 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG cosTemplates 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cosTemplate 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG krbContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Password Policy 2025-05-07T18:06:32Z DEBUG cosPriority: 2025-05-07T18:06:32Z DEBUG 10000000000 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:32Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cosTemplate 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG krbContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Password Policy 2025-05-07T18:06:32Z DEBUG cosPriority: 2025-05-07T18:06:32Z DEBUG 10000000000 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:32Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Password Policy,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG description: 2025-05-07T18:06:32Z DEBUG Default Password Policy for Hosts 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ldapsubentry 2025-05-07T18:06:32Z DEBUG cosSuperDefinition 2025-05-07T18:06:32Z DEBUG cosPointerDefinition 2025-05-07T18:06:32Z DEBUG cosTemplateDn: 2025-05-07T18:06:32Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG cosAttribute: 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference default 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG description: 2025-05-07T18:06:32Z DEBUG Default Password Policy for Hosts 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ldapsubentry 2025-05-07T18:06:32Z DEBUG cosSuperDefinition 2025-05-07T18:06:32Z DEBUG cosPointerDefinition 2025-05-07T18:06:32Z DEBUG cosTemplateDn: 2025-05-07T18:06:32Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG cosAttribute: 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference default 2025-05-07T18:06:32Z DEBUG New entry: cn=cosTemplates,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG cosTemplates 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG cosTemplates 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cosTemplate 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG krbContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Password Policy 2025-05-07T18:06:32Z DEBUG cosPriority: 2025-05-07T18:06:32Z DEBUG 10000000000 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:32Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cosTemplate 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG krbContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Password Policy 2025-05-07T18:06:32Z DEBUG cosPriority: 2025-05-07T18:06:32Z DEBUG 10000000000 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:32Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Password Policy,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG description: 2025-05-07T18:06:32Z DEBUG Default Password Policy for Services 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ldapsubentry 2025-05-07T18:06:32Z DEBUG cosSuperDefinition 2025-05-07T18:06:32Z DEBUG cosPointerDefinition 2025-05-07T18:06:32Z DEBUG cosTemplateDn: 2025-05-07T18:06:32Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG cosAttribute: 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference default 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG description: 2025-05-07T18:06:32Z DEBUG Default Password Policy for Services 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ldapsubentry 2025-05-07T18:06:32Z DEBUG cosSuperDefinition 2025-05-07T18:06:32Z DEBUG cosPointerDefinition 2025-05-07T18:06:32Z DEBUG cosTemplateDn: 2025-05-07T18:06:32Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG cosAttribute: 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference default 2025-05-07T18:06:32Z DEBUG New entry: cn=cosTemplates,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=cosTemplates,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG cosTemplates 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=cosTemplates,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG cosTemplates 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cosTemplate 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG krbContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Password Policy 2025-05-07T18:06:32Z DEBUG cosPriority: 2025-05-07T18:06:32Z DEBUG 10000000000 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:32Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cosTemplate 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG krbContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Password Policy 2025-05-07T18:06:32Z DEBUG cosPriority: 2025-05-07T18:06:32Z DEBUG 10000000000 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:32Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG description: 2025-05-07T18:06:32Z DEBUG Default Password Policy for Kerberos Services 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ldapsubentry 2025-05-07T18:06:32Z DEBUG cosSuperDefinition 2025-05-07T18:06:32Z DEBUG cosPointerDefinition 2025-05-07T18:06:32Z DEBUG cosTemplateDn: 2025-05-07T18:06:32Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG cosAttribute: 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference default 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG description: 2025-05-07T18:06:32Z DEBUG Default Password Policy for Kerberos Services 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ldapsubentry 2025-05-07T18:06:32Z DEBUG cosSuperDefinition 2025-05-07T18:06:32Z DEBUG cosPointerDefinition 2025-05-07T18:06:32Z DEBUG cosTemplateDn: 2025-05-07T18:06:32Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG cosAttribute: 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference default 2025-05-07T18:06:32Z DEBUG New entry: cn=cosTemplates,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=cosTemplates,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG cosTemplates 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=cosTemplates,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG cosTemplates 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cosTemplate 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG krbContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Password Policy 2025-05-07T18:06:32Z DEBUG cosPriority: 2025-05-07T18:06:32Z DEBUG 10000000000 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:32Z DEBUG cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectclass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG cosTemplate 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG krbContainer 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Default Password Policy 2025-05-07T18:06:32Z DEBUG cosPriority: 2025-05-07T18:06:32Z DEBUG 10000000000 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:32Z DEBUG cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG New entry: cn=Default Password Policy,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG description: 2025-05-07T18:06:32Z DEBUG Default Password Policy for System Accounts 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ldapsubentry 2025-05-07T18:06:32Z DEBUG cosSuperDefinition 2025-05-07T18:06:32Z DEBUG cosPointerDefinition 2025-05-07T18:06:32Z DEBUG cosTemplateDn: 2025-05-07T18:06:32Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG cosAttribute: 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference default 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Default Password Policy,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG description: 2025-05-07T18:06:32Z DEBUG Default Password Policy for System Accounts 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG ldapsubentry 2025-05-07T18:06:32Z DEBUG cosSuperDefinition 2025-05-07T18:06:32Z DEBUG cosPointerDefinition 2025-05-07T18:06:32Z DEBUG cosTemplateDn: 2025-05-07T18:06:32Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG cosAttribute: 2025-05-07T18:06:32Z DEBUG krbPwdPolicyReference default 2025-05-07T18:06:32Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-default_password_policy.update 0.625 sec 2025-05-07T18:06:32Z DEBUG Parsing update file '/usr/share/ipa/updates/20-dna.update' 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ipa-winsync 2025-05-07T18:06:32Z DEBUG ipawinsyncacctdisable: 2025-05-07T18:06:32Z DEBUG both 2025-05-07T18:06:32Z DEBUG ipawinsyncdefaultgroupattr: 2025-05-07T18:06:32Z DEBUG ipaDefaultPrimaryGroup 2025-05-07T18:06:32Z DEBUG ipawinsyncdefaultgroupfilter: 2025-05-07T18:06:32Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2025-05-07T18:06:32Z DEBUG ipawinsyncforcesync: 2025-05-07T18:06:32Z DEBUG true 2025-05-07T18:06:32Z DEBUG ipawinsynchomedirattr: 2025-05-07T18:06:32Z DEBUG ipaHomesRootDir 2025-05-07T18:06:32Z DEBUG ipawinsyncloginshellattr: 2025-05-07T18:06:32Z DEBUG ipaDefaultLoginShell 2025-05-07T18:06:32Z DEBUG ipawinsyncnewentryfilter: 2025-05-07T18:06:32Z DEBUG (cn=ipaConfig) 2025-05-07T18:06:32Z DEBUG ipawinsyncnewuserocattr: 2025-05-07T18:06:32Z DEBUG ipauserobjectclasses 2025-05-07T18:06:32Z DEBUG ipawinsyncrealmattr: 2025-05-07T18:06:32Z DEBUG cn 2025-05-07T18:06:32Z DEBUG ipawinsyncrealmfilter: 2025-05-07T18:06:32Z DEBUG (objectclass=krbRealmContainer) 2025-05-07T18:06:32Z DEBUG ipawinsyncuserattr: 2025-05-07T18:06:32Z DEBUG uidNumber -1 2025-05-07T18:06:32Z DEBUG gidNumber -1 2025-05-07T18:06:32Z DEBUG ipawinsyncuserflatten: 2025-05-07T18:06:32Z DEBUG true 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG ipa winsync plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG ipa-winsync-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG ipa_winsync_plugin_init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libipa_winsync 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG preoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG FreeIPA project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG FreeIPA/1.0 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:32Z DEBUG 60 2025-05-07T18:06:32Z DEBUG remove: 'uidNumber 999' from ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2025-05-07T18:06:32Z DEBUG remove: 'uidNumber 999' not in ipaWinSyncUserAttr 2025-05-07T18:06:32Z DEBUG remove: 'gidNumber 999' from ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2025-05-07T18:06:32Z DEBUG remove: 'gidNumber 999' not in ipaWinSyncUserAttr 2025-05-07T18:06:32Z DEBUG add: 'uidNumber -1' to ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2025-05-07T18:06:32Z DEBUG add: updated value ['gidNumber -1', 'uidNumber -1'] 2025-05-07T18:06:32Z DEBUG add: 'gidNumber -1' to ipaWinSyncUserAttr, current value ['gidNumber -1', 'uidNumber -1'] 2025-05-07T18:06:32Z DEBUG add: updated value ['uidNumber -1', 'gidNumber -1'] 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ipa-winsync 2025-05-07T18:06:32Z DEBUG ipawinsyncacctdisable: 2025-05-07T18:06:32Z DEBUG both 2025-05-07T18:06:32Z DEBUG ipawinsyncdefaultgroupattr: 2025-05-07T18:06:32Z DEBUG ipaDefaultPrimaryGroup 2025-05-07T18:06:32Z DEBUG ipawinsyncdefaultgroupfilter: 2025-05-07T18:06:32Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2025-05-07T18:06:32Z DEBUG ipawinsyncforcesync: 2025-05-07T18:06:32Z DEBUG true 2025-05-07T18:06:32Z DEBUG ipawinsynchomedirattr: 2025-05-07T18:06:32Z DEBUG ipaHomesRootDir 2025-05-07T18:06:32Z DEBUG ipawinsyncloginshellattr: 2025-05-07T18:06:32Z DEBUG ipaDefaultLoginShell 2025-05-07T18:06:32Z DEBUG ipawinsyncnewentryfilter: 2025-05-07T18:06:32Z DEBUG (cn=ipaConfig) 2025-05-07T18:06:32Z DEBUG ipawinsyncnewuserocattr: 2025-05-07T18:06:32Z DEBUG ipauserobjectclasses 2025-05-07T18:06:32Z DEBUG ipawinsyncrealmattr: 2025-05-07T18:06:32Z DEBUG cn 2025-05-07T18:06:32Z DEBUG ipawinsyncrealmfilter: 2025-05-07T18:06:32Z DEBUG (objectclass=krbRealmContainer) 2025-05-07T18:06:32Z DEBUG ipawinsyncuserattr: 2025-05-07T18:06:32Z DEBUG uidNumber -1 2025-05-07T18:06:32Z DEBUG gidNumber -1 2025-05-07T18:06:32Z DEBUG ipawinsyncuserflatten: 2025-05-07T18:06:32Z DEBUG true 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG ipa winsync plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG ipa-winsync-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG ipa_winsync_plugin_init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libipa_winsync 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG preoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG FreeIPA project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG FreeIPA/1.0 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:32Z DEBUG 60 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-dna.update 0.011 sec 2025-05-07T18:06:32Z DEBUG Parsing update file '/usr/share/ipa/updates/20-enable_dirsrv_plugins.update' 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG 7-bit check 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG Enforce 7-bit clean attribute values 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG NS7bitAttr 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG NS7bitAttr_Init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libattr-unique-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG betxnpreoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG nsslapd-pluginarg0: 2025-05-07T18:06:32Z DEBUG uid 2025-05-07T18:06:32Z DEBUG nsslapd-pluginarg1: 2025-05-07T18:06:32Z DEBUG mail 2025-05-07T18:06:32Z DEBUG nsslapd-pluginarg2: 2025-05-07T18:06:32Z DEBUG , 2025-05-07T18:06:32Z DEBUG nsslapd-pluginarg3: 2025-05-07T18:06:32Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG replace: off not found, skipping 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG 7-bit check 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG Enforce 7-bit clean attribute values 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG NS7bitAttr 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG NS7bitAttr_Init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libattr-unique-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG betxnpreoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG nsslapd-pluginarg0: 2025-05-07T18:06:32Z DEBUG uid 2025-05-07T18:06:32Z DEBUG nsslapd-pluginarg1: 2025-05-07T18:06:32Z DEBUG mail 2025-05-07T18:06:32Z DEBUG nsslapd-pluginarg2: 2025-05-07T18:06:32Z DEBUG , 2025-05-07T18:06:32Z DEBUG nsslapd-pluginarg3: 2025-05-07T18:06:32Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=Account Usability Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Account Usability Plugin 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG Account Usability Control plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG Account Usability Control 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG auc_init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libacctusability-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG preoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG replace: off not found, skipping 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Account Usability Plugin 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG Account Usability Control plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG Account Usability Control 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG auc_init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libacctusability-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG preoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=ACL Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ACL Plugin 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG acl access check plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG acl 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG acl_init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libacl-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG accesscontrol 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG replace: off not found, skipping 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ACL Plugin 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG acl access check plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG acl 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG acl_init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libacl-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG accesscontrol 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=ACL preoperation,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ACL preoperation 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG acl access check plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG acl 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG acl_preopInit 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libacl-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG preoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG replace: off not found, skipping 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG ACL preoperation 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG acl access check plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG acl 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG acl_preopInit 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libacl-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG preoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:32Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Initial value 2025-05-07T18:06:32Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG automemberprocessmodifyops: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Auto Membership Plugin 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:32Z DEBUG cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG Auto Membership plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG Auto Membership 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG automember_init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libautomember-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG betxnpreoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG replace: off not found, skipping 2025-05-07T18:06:32Z DEBUG --------------------------------------------- 2025-05-07T18:06:32Z DEBUG Final value after applying updates 2025-05-07T18:06:32Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2025-05-07T18:06:32Z DEBUG automemberprocessmodifyops: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG cn: 2025-05-07T18:06:32Z DEBUG Auto Membership Plugin 2025-05-07T18:06:32Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:32Z DEBUG database 2025-05-07T18:06:32Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:32Z DEBUG cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:32Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:32Z DEBUG Auto Membership plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:32Z DEBUG on 2025-05-07T18:06:32Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:32Z DEBUG Auto Membership 2025-05-07T18:06:32Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:32Z DEBUG automember_init 2025-05-07T18:06:32Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:32Z DEBUG libautomember-plugin 2025-05-07T18:06:32Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:32Z DEBUG betxnpreoperation 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:32Z DEBUG 389 Project 2025-05-07T18:06:32Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:32Z DEBUG 3.1.2 2025-05-07T18:06:32Z DEBUG objectClass: 2025-05-07T18:06:32Z DEBUG top 2025-05-07T18:06:32Z DEBUG nsSlapdPlugin 2025-05-07T18:06:32Z DEBUG extensibleObject 2025-05-07T18:06:32Z DEBUG [] 2025-05-07T18:06:32Z DEBUG Updated 0 2025-05-07T18:06:32Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=Bitwise Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Bitwise Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG bitwise match plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG bitwise 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG bitwise_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libbitwise-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG matchingRule 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Bitwise Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG bitwise match plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG bitwise 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG bitwise_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libbitwise-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG matchingRule 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=chaining database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG chaining database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG LDAP chaining backend database plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG chaining database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG chaining_back_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libchainingdb-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG chaining database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG LDAP chaining backend database plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG chaining database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG chaining_back_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libchainingdb-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=Class of Service,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Class of Service 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:33Z DEBUG State Change Plugin 2025-05-07T18:06:33Z DEBUG Views 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG class of service plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG cos 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG cos_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libcos-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Class of Service 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:33Z DEBUG State Change Plugin 2025-05-07T18:06:33Z DEBUG Views 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG class of service plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG cos 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG cos_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libcos-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=deref,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=deref,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG deref 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG Dereference plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG Dereference 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG deref_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libderef-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG preoperation 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG nsContainer 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=deref,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG deref 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG Dereference plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG Dereference 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG deref_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libderef-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG preoperation 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG nsContainer 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG New entry: cn=HTTP Client,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=Internationalization Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Internationalization Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG internationalized ordering rule plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG orderingrule 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG orderingRule_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libcollation-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG matchingRule 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG nsslapd-pluginarg0: 2025-05-07T18:06:33Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/slapd-collations.conf 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Internationalization Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG internationalized ordering rule plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG orderingrule 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG orderingRule_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libcollation-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG matchingRule 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG nsslapd-pluginarg0: 2025-05-07T18:06:33Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/slapd-collations.conf 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Linked Attributes 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG Linked Attributes plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG Linked Attributes 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG linked_attrs_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG liblinkedattrs-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG betxnpreoperation 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG nsContainer 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Linked Attributes 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG Linked Attributes plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG Linked Attributes 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG linked_attrs_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG liblinkedattrs-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG betxnpreoperation 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG nsContainer 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Managed Entries 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:33Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG Managed Entries plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG Managed Entries 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG mep_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libmanagedentries-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG betxnpreoperation 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG nsContainer 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Managed Entries 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:33Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG Managed Entries plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG Managed Entries 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG mep_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libmanagedentries-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG betxnpreoperation 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG nsContainer 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Multisupplier Replication Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:33Z DEBUG ldbm database 2025-05-07T18:06:33Z DEBUG AES 2025-05-07T18:06:33Z DEBUG Class of Service 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG Multi-supplier Replication Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG replication-multisupplier 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG replication_multisupplier_plugin_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libreplication-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Multisupplier Replication Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:33Z DEBUG ldbm database 2025-05-07T18:06:33Z DEBUG AES 2025-05-07T18:06:33Z DEBUG Class of Service 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG Multi-supplier Replication Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG replication-multisupplier 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG replication_multisupplier_plugin_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libreplication-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Roles Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:33Z DEBUG State Change Plugin 2025-05-07T18:06:33Z DEBUG Views 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG roles plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG roles 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG roles_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libroles-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Roles Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:33Z DEBUG State Change Plugin 2025-05-07T18:06:33Z DEBUG Views 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG roles plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG roles 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG roles_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libroles-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=Schema Reload,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Schema Reload 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG task plugin to reload schema files 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG schemareload 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG schemareload_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libschemareload-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Schema Reload 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG task plugin to reload schema files 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG schemareload 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG schemareload_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libschemareload-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG State Change Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG state change notification service plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG statechange 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG statechange_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libstatechange-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG betxnpostoperation 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG State Change Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG state change notification service plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG statechange 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG statechange_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libstatechange-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG betxnpostoperation 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=Views,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=Views,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Views 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:33Z DEBUG State Change Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG virtual directory information tree views plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG views 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG views_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libviews-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=Views,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG Views 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:33Z DEBUG State Change Plugin 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG virtual directory information tree views plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG views 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG views_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libviews-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG object 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG whoami 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG whoami extended operation plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG whoami-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG whoami_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libwhoami-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG extendedop 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG replace: off not found, skipping 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG whoami 2025-05-07T18:06:33Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:33Z DEBUG database 2025-05-07T18:06:33Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:33Z DEBUG whoami extended operation plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:33Z DEBUG on 2025-05-07T18:06:33Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:33Z DEBUG whoami-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:33Z DEBUG whoami_init 2025-05-07T18:06:33Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:33Z DEBUG libwhoami-plugin 2025-05-07T18:06:33Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:33Z DEBUG extendedop 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:33Z DEBUG 389 Project 2025-05-07T18:06:33Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:33Z DEBUG 3.1.2 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsSlapdPlugin 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-enable_dirsrv_plugins.update 0.294 sec 2025-05-07T18:06:33Z DEBUG Parsing update file '/usr/share/ipa/updates/20-host_nis_groups.update' 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG mepTemplateEntry 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG NGP HGP Template 2025-05-07T18:06:33Z DEBUG mepRDNAttr: 2025-05-07T18:06:33Z DEBUG cn 2025-05-07T18:06:33Z DEBUG mepStaticAttr: 2025-05-07T18:06:33Z DEBUG ipaUniqueId: autogenerate 2025-05-07T18:06:33Z DEBUG objectclass: ipanisnetgroup 2025-05-07T18:06:33Z DEBUG objectclass: ipaobject 2025-05-07T18:06:33Z DEBUG nisDomainName: ufreeipa.test 2025-05-07T18:06:33Z DEBUG mepMappedAttr: 2025-05-07T18:06:33Z DEBUG cn: $cn 2025-05-07T18:06:33Z DEBUG memberHost: $dn 2025-05-07T18:06:33Z DEBUG description: ipaNetgroup $cn 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG mepTemplateEntry 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG NGP HGP Template 2025-05-07T18:06:33Z DEBUG mepRDNAttr: 2025-05-07T18:06:33Z DEBUG cn 2025-05-07T18:06:33Z DEBUG mepStaticAttr: 2025-05-07T18:06:33Z DEBUG ipaUniqueId: autogenerate 2025-05-07T18:06:33Z DEBUG objectclass: ipanisnetgroup 2025-05-07T18:06:33Z DEBUG objectclass: ipaobject 2025-05-07T18:06:33Z DEBUG nisDomainName: ufreeipa.test 2025-05-07T18:06:33Z DEBUG mepMappedAttr: 2025-05-07T18:06:33Z DEBUG cn: $cn 2025-05-07T18:06:33Z DEBUG memberHost: $dn 2025-05-07T18:06:33Z DEBUG description: ipaNetgroup $cn 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG NGP Definition 2025-05-07T18:06:33Z DEBUG originScope: 2025-05-07T18:06:33Z DEBUG cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG originFilter: 2025-05-07T18:06:33Z DEBUG objectclass=ipahostgroup 2025-05-07T18:06:33Z DEBUG managedBase: 2025-05-07T18:06:33Z DEBUG cn=ng,cn=alt,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG managedTemplate: 2025-05-07T18:06:33Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG only: set cn to 'NGP Definition', current value ['NGP Definition'] 2025-05-07T18:06:33Z DEBUG only: updated value ['NGP Definition'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG extensibleObject 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG NGP Definition 2025-05-07T18:06:33Z DEBUG originScope: 2025-05-07T18:06:33Z DEBUG cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG originFilter: 2025-05-07T18:06:33Z DEBUG objectclass=ipahostgroup 2025-05-07T18:06:33Z DEBUG managedBase: 2025-05-07T18:06:33Z DEBUG cn=ng,cn=alt,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG managedTemplate: 2025-05-07T18:06:33Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-host_nis_groups.update 0.034 sec 2025-05-07T18:06:33Z DEBUG Parsing update file '/usr/share/ipa/updates/20-indices.update' 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG accessRuleType 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'accessRuleType', current value ['accessRuleType'] 2025-05-07T18:06:33Z DEBUG only: updated value ['accessRuleType'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG accessRuleType 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG altSecurityIdentities 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'altSecurityIdentities', current value ['altSecurityIdentities'] 2025-05-07T18:06:33Z DEBUG only: updated value ['altSecurityIdentities'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG altSecurityIdentities 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG automountkey 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'automountkey', current value ['automountkey'] 2025-05-07T18:06:33Z DEBUG only: updated value ['automountkey'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG automountkey 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG automountMapName 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'automountMapName', current value ['automountMapName'] 2025-05-07T18:06:33Z DEBUG only: updated value ['automountMapName'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG automountMapName 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG carLicense 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'carLicense', current value ['carLicense'] 2025-05-07T18:06:33Z DEBUG only: updated value ['carLicense'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG carLicense 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG description 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'description', current value ['description'] 2025-05-07T18:06:33Z DEBUG only: updated value ['description'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG description 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG displayname 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'displayname', current value ['displayname'] 2025-05-07T18:06:33Z DEBUG only: updated value ['displayname'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG displayname 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG fqdn 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'fqdn', current value ['fqdn'] 2025-05-07T18:06:33Z DEBUG only: updated value ['fqdn'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG fqdn 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG gidnumber 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'gidnumber', current value ['gidnumber'] 2025-05-07T18:06:33Z DEBUG only: updated value ['gidnumber'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG gidnumber 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG hostCategory 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'hostCategory', current value ['hostCategory'] 2025-05-07T18:06:33Z DEBUG only: updated value ['hostCategory'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG hostCategory 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG idnsName 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'idnsName', current value ['idnsName'] 2025-05-07T18:06:33Z DEBUG only: updated value ['idnsName'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG idnsName 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaallowedtarget 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaallowedtarget', current value ['ipaallowedtarget'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaallowedtarget'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaallowedtarget 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaAnchorUUID 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaAnchorUUID', current value ['ipaAnchorUUID'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaAnchorUUID'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaAnchorUUID 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaassignedidview 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaassignedidview', current value ['ipaassignedidview'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaassignedidview'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaassignedidview 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaCASubjectDN 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaCASubjectDN', current value ['ipaCASubjectDN'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaCASubjectDN'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaCASubjectDN 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaCertmapData 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaCertmapData', current value ['ipaCertmapData'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaCertmapData'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaCertmapData 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaConfigString 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaConfigString', current value ['ipaConfigString'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaConfigString'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaConfigString 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaEnabledFlag 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaEnabledFlag', current value ['ipaEnabledFlag'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaEnabledFlag'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaEnabledFlag 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaExternalMember 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaExternalMember', current value ['ipaExternalMember'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaExternalMember'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaExternalMember 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaIdpDevAuthEndpoint 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaIdpDevAuthEndpoint', current value ['ipaIdpDevAuthEndpoint'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaIdpDevAuthEndpoint'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaIdpDevAuthEndpoint 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaIdpAuthEndpoint 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaIdpAuthEndpoint', current value ['ipaIdpAuthEndpoint'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaIdpAuthEndpoint'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaIdpAuthEndpoint 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaIdpScope 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaIdpScope', current value ['ipaIdpScope'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaIdpScope'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaIdpScope 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaIdpTokenEndpoint 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaIdpTokenEndpoint', current value ['ipaIdpTokenEndpoint'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaIdpTokenEndpoint'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaIdpTokenEndpoint 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaKrbAuthzData 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaKrbAuthzData', current value ['ipaKrbAuthzData'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaKrbAuthzData'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaKrbAuthzData 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipakrbprincipalalias 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipakrbprincipalalias', current value ['ipakrbprincipalalias'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipakrbprincipalalias'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipakrbprincipalalias 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipalocation 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipalocation', current value ['ipalocation'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipalocation'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipalocation 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaMemberCa 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaMemberCa', current value ['ipaMemberCa'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaMemberCa'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaMemberCa 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaMemberCertProfile 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaMemberCertProfile', current value ['ipaMemberCertProfile'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaMemberCertProfile'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaMemberCertProfile 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaNTSecurityIdentifier 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaNTSecurityIdentifier', current value ['ipaNTSecurityIdentifier'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaNTSecurityIdentifier'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaNTSecurityIdentifier 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaNTTrustPartner 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaNTTrustPartner', current value ['ipaNTTrustPartner'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaNTTrustPartner'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaNTTrustPartner 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaOriginalUid 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaOriginalUid', current value ['ipaOriginalUid'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaOriginalUid'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaOriginalUid 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaOwner 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaOwner', current value ['ipaOwner'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaOwner'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaOwner 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipasudorunas 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipasudorunas', current value ['ipasudorunas'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipasudorunas'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipasudorunas 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaSubGidNumber 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaSubGidNumber', current value ['ipaSubGidNumber'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaSubGidNumber'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaSubGidNumber 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaSubUidNumber 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipaSubUidNumber', current value ['ipaSubUidNumber'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipaSubUidNumber'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaSubUidNumber 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG sudoorder 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'sudoorder', current value ['sudoorder'] 2025-05-07T18:06:33Z DEBUG only: updated value ['sudoorder'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG sudoorder 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipasudorunasgroup 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipasudorunasgroup', current value ['ipasudorunasgroup'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipasudorunasgroup'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipasudorunasgroup 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipatokenradiusconfiglink 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipatokenradiusconfiglink', current value ['ipatokenradiusconfiglink'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipatokenradiusconfiglink'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipatokenradiusconfiglink 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipauniqueid 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipauniqueid', current value ['ipauniqueid'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipauniqueid'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipauniqueid 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipServicePort 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ipServicePort', current value ['ipServicePort'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ipServicePort'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipServicePort 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG krbCanonicalName 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'krbCanonicalName', current value ['krbCanonicalName'] 2025-05-07T18:06:33Z DEBUG only: updated value ['krbCanonicalName'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG krbCanonicalName 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG krbPasswordExpiration 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'krbPasswordExpiration', current value ['krbPasswordExpiration'] 2025-05-07T18:06:33Z DEBUG only: updated value ['krbPasswordExpiration'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG krbPasswordExpiration 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG krbPrincipalName 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG caseIgnoreIA5Match 2025-05-07T18:06:33Z DEBUG caseExactIA5Match 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'krbPrincipalName', current value ['krbPrincipalName'] 2025-05-07T18:06:33Z DEBUG only: updated value ['krbPrincipalName'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: 'caseIgnoreIA5Match' to nsMatchingRule, current value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2025-05-07T18:06:33Z DEBUG add: updated value ['caseExactIA5Match', 'caseIgnoreIA5Match'] 2025-05-07T18:06:33Z DEBUG add: 'caseExactIA5Match' to nsMatchingRule, current value ['caseExactIA5Match', 'caseIgnoreIA5Match'] 2025-05-07T18:06:33Z DEBUG add: updated value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG krbPrincipalName 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG caseIgnoreIA5Match 2025-05-07T18:06:33Z DEBUG caseExactIA5Match 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG l 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'l', current value ['l'] 2025-05-07T18:06:33Z DEBUG only: updated value ['l'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG l 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG macAddress 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'macAddress', current value ['macAddress'] 2025-05-07T18:06:33Z DEBUG only: updated value ['macAddress'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG macAddress 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG managedby 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'managedby', current value ['managedby'] 2025-05-07T18:06:33Z DEBUG only: updated value ['managedby'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG managedby 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG manager 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'manager', current value ['manager'] 2025-05-07T18:06:33Z DEBUG only: updated value ['manager'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG manager 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG member 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'member', current value ['member'] 2025-05-07T18:06:33Z DEBUG only: updated value ['member'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG member 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberallowcmd 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'memberallowcmd', current value ['memberallowcmd'] 2025-05-07T18:06:33Z DEBUG only: updated value ['memberallowcmd'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberallowcmd 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberdenycmd 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'memberdenycmd', current value ['memberdenycmd'] 2025-05-07T18:06:33Z DEBUG only: updated value ['memberdenycmd'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberdenycmd 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberHost 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'memberHost', current value ['memberHost'] 2025-05-07T18:06:33Z DEBUG only: updated value ['memberHost'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberHost 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberManager 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'memberManager', current value ['memberManager'] 2025-05-07T18:06:33Z DEBUG only: updated value ['memberManager'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberManager 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberOf 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'memberOf', current value ['memberOf'] 2025-05-07T18:06:33Z DEBUG only: updated value ['memberOf'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberOf 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberPrincipal 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'memberPrincipal', current value ['memberPrincipal'] 2025-05-07T18:06:33Z DEBUG only: updated value ['memberPrincipal'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberPrincipal 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberservice 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'memberservice', current value ['memberservice'] 2025-05-07T18:06:33Z DEBUG only: updated value ['memberservice'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberservice 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberuid 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'memberuid', current value ['memberuid'] 2025-05-07T18:06:33Z DEBUG only: updated value ['memberuid'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberuid 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberUser 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'memberUser', current value ['memberUser'] 2025-05-07T18:06:33Z DEBUG only: updated value ['memberUser'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG memberUser 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG nsHardwarePlatform 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'nsHardwarePlatform', current value ['nsHardwarePlatform'] 2025-05-07T18:06:33Z DEBUG only: updated value ['nsHardwarePlatform'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG nsHardwarePlatform 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG nsHostLocation 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'nsHostLocation', current value ['nsHostLocation'] 2025-05-07T18:06:33Z DEBUG only: updated value ['nsHostLocation'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG nsHostLocation 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG nsOsVersion 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'nsOsVersion', current value ['nsOsVersion'] 2025-05-07T18:06:33Z DEBUG only: updated value ['nsOsVersion'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG nsOsVersion 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsindex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ntUniqueId 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'ntUniqueId', current value ['ntUniqueId'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ntUniqueId'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ntUniqueId 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ntUserDomainId 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'ntUserDomainId', current value ['ntUserDomainId'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ntUserDomainId'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ntUserDomainId 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ou 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'ou', current value ['ou'] 2025-05-07T18:06:33Z DEBUG only: updated value ['ou'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ou 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG owner 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'owner', current value ['owner'] 2025-05-07T18:06:33Z DEBUG only: updated value ['owner'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG owner 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG secretary 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'secretary', current value ['secretary'] 2025-05-07T18:06:33Z DEBUG only: updated value ['secretary'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG secretary 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG seealso 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'seealso', current value ['seealso'] 2025-05-07T18:06:33Z DEBUG only: updated value ['seealso'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG seealso 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG serverhostname 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'serverhostname', current value ['serverhostname'] 2025-05-07T18:06:33Z DEBUG only: updated value ['serverhostname'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG serverhostname 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG sourcehost 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'sourcehost', current value ['sourcehost'] 2025-05-07T18:06:33Z DEBUG only: updated value ['sourcehost'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG sourcehost 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG title 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'title', current value ['title'] 2025-05-07T18:06:33Z DEBUG only: updated value ['title'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG title 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG uid 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'uid', current value ['uid'] 2025-05-07T18:06:33Z DEBUG only: updated value ['uid'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG uid 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG uidnumber 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'uidnumber', current value ['uidnumber'] 2025-05-07T18:06:33Z DEBUG only: updated value ['uidnumber'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:33Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG add: updated value ['integerOrderingMatch'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG uidnumber 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG nsMatchingRule: 2025-05-07T18:06:33Z DEBUG integerOrderingMatch 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG uniquemember 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG only: set cn to 'uniquemember', current value ['uniquemember'] 2025-05-07T18:06:33Z DEBUG only: updated value ['uniquemember'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG add: updated value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'sub'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG uniquemember 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG sub 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG userCertificate 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG only: set cn to 'userCertificate', current value ['userCertificate'] 2025-05-07T18:06:33Z DEBUG only: updated value ['userCertificate'] 2025-05-07T18:06:33Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG add: updated value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2025-05-07T18:06:33Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG userCertificate 2025-05-07T18:06:33Z DEBUG nsIndexType: 2025-05-07T18:06:33Z DEBUG eq 2025-05-07T18:06:33Z DEBUG pres 2025-05-07T18:06:33Z DEBUG nsSystemIndex: 2025-05-07T18:06:33Z DEBUG false 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG nsIndex 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-indices.update 0.764 sec 2025-05-07T18:06:33Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG groupOfNames 2025-05-07T18:06:33Z DEBUG nestedGroup 2025-05-07T18:06:33Z DEBUG ipaobject 2025-05-07T18:06:33Z DEBUG ipahostgroup 2025-05-07T18:06:33Z DEBUG description: 2025-05-07T18:06:33Z DEBUG IPA server hosts 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaservers 2025-05-07T18:06:33Z DEBUG ipaUniqueID: 2025-05-07T18:06:33Z DEBUG 6b730f14-2b6d-11f0-9ff4-fa163e36f7a6 2025-05-07T18:06:33Z DEBUG member: 2025-05-07T18:06:33Z DEBUG fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG groupOfNames 2025-05-07T18:06:33Z DEBUG nestedGroup 2025-05-07T18:06:33Z DEBUG ipaobject 2025-05-07T18:06:33Z DEBUG ipahostgroup 2025-05-07T18:06:33Z DEBUG description: 2025-05-07T18:06:33Z DEBUG IPA server hosts 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaservers 2025-05-07T18:06:33Z DEBUG ipaUniqueID: 2025-05-07T18:06:33Z DEBUG 6b730f14-2b6d-11f0-9ff4-fa163e36f7a6 2025-05-07T18:06:33Z DEBUG member: 2025-05-07T18:06:33Z DEBUG fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG groupOfNames 2025-05-07T18:06:33Z DEBUG nestedGroup 2025-05-07T18:06:33Z DEBUG ipaobject 2025-05-07T18:06:33Z DEBUG ipahostgroup 2025-05-07T18:06:33Z DEBUG description: 2025-05-07T18:06:33Z DEBUG IPA server hosts 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaservers 2025-05-07T18:06:33Z DEBUG ipaUniqueID: 2025-05-07T18:06:33Z DEBUG 6b730f14-2b6d-11f0-9ff4-fa163e36f7a6 2025-05-07T18:06:33Z DEBUG member: 2025-05-07T18:06:33Z DEBUG fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG add: 'fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test' to member, current value ['fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:33Z DEBUG add: updated value ['fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG groupOfNames 2025-05-07T18:06:33Z DEBUG nestedGroup 2025-05-07T18:06:33Z DEBUG ipaobject 2025-05-07T18:06:33Z DEBUG ipahostgroup 2025-05-07T18:06:33Z DEBUG description: 2025-05-07T18:06:33Z DEBUG IPA server hosts 2025-05-07T18:06:33Z DEBUG cn: 2025-05-07T18:06:33Z DEBUG ipaservers 2025-05-07T18:06:33Z DEBUG ipaUniqueID: 2025-05-07T18:06:33Z DEBUG 6b730f14-2b6d-11f0-9ff4-fa163e36f7a6 2025-05-07T18:06:33Z DEBUG member: 2025-05-07T18:06:33Z DEBUG fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG [] 2025-05-07T18:06:33Z DEBUG Updated 0 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:33Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-ipaservers_hostgroup.update 0.011 sec 2025-05-07T18:06:33Z DEBUG Parsing update file '/usr/share/ipa/updates/20-nss_ldap.update' 2025-05-07T18:06:33Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Initial value 2025-05-07T18:06:33Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG domain 2025-05-07T18:06:33Z DEBUG pilotObject 2025-05-07T18:06:33Z DEBUG dc: 2025-05-07T18:06:33Z DEBUG ufreeipa 2025-05-07T18:06:33Z DEBUG info: 2025-05-07T18:06:33Z DEBUG IPA V2.0 2025-05-07T18:06:33Z DEBUG aci: 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:33Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:33Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:33Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:33Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:33Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:33Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:33Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG add: 'domain' to objectClass, current value ['top', 'domain', 'pilotObject'] 2025-05-07T18:06:33Z DEBUG add: updated value ['top', 'pilotObject', 'domain'] 2025-05-07T18:06:33Z DEBUG add: 'domainRelatedObject' to objectClass, current value ['top', 'pilotObject', 'domain'] 2025-05-07T18:06:33Z DEBUG add: updated value ['top', 'pilotObject', 'domain', 'domainRelatedObject'] 2025-05-07T18:06:33Z DEBUG add: 'nisDomainObject' to objectClass, current value ['top', 'pilotObject', 'domain', 'domainRelatedObject'] 2025-05-07T18:06:33Z DEBUG add: updated value ['top', 'pilotObject', 'domain', 'domainRelatedObject', 'nisDomainObject'] 2025-05-07T18:06:33Z DEBUG add: 'ufreeipa.test' to associatedDomain, current value [] 2025-05-07T18:06:33Z DEBUG add: updated value ['ufreeipa.test'] 2025-05-07T18:06:33Z DEBUG add: 'ufreeipa.test' to nisDomain, current value [] 2025-05-07T18:06:33Z DEBUG add: updated value ['ufreeipa.test'] 2025-05-07T18:06:33Z DEBUG --------------------------------------------- 2025-05-07T18:06:33Z DEBUG Final value after applying updates 2025-05-07T18:06:33Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:33Z DEBUG objectClass: 2025-05-07T18:06:33Z DEBUG top 2025-05-07T18:06:33Z DEBUG pilotObject 2025-05-07T18:06:33Z DEBUG domain 2025-05-07T18:06:33Z DEBUG domainRelatedObject 2025-05-07T18:06:33Z DEBUG nisDomainObject 2025-05-07T18:06:33Z DEBUG dc: 2025-05-07T18:06:33Z DEBUG ufreeipa 2025-05-07T18:06:33Z DEBUG info: 2025-05-07T18:06:33Z DEBUG IPA V2.0 2025-05-07T18:06:33Z DEBUG aci: 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:33Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:33Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:33Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:33Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:33Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:33Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:33Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:33Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:33Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:33Z DEBUG associatedDomain: 2025-05-07T18:06:33Z DEBUG ufreeipa.test 2025-05-07T18:06:33Z DEBUG nisDomain: 2025-05-07T18:06:33Z DEBUG ufreeipa.test 2025-05-07T18:06:33Z DEBUG [(0, 'objectClass', ['domainRelatedObject', 'nisDomainObject']), (2, 'associatedDomain', ['ufreeipa.test']), (2, 'nisDomain', ['ufreeipa.test'])] 2025-05-07T18:06:33Z DEBUG Updated 1 2025-05-07T18:06:33Z DEBUG update_entry modlist [(0, 'objectClass', [b'domainRelatedObject', b'nisDomainObject']), (2, 'associatedDomain', [b'ufreeipa.test']), (2, 'nisDomain', [b'ufreeipa.test'])] 2025-05-07T18:06:33Z DEBUG Done 2025-05-07T18:06:34Z DEBUG New entry: ou=profile,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: ou=profile,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG add: 'top' to objectClass, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['top'] 2025-05-07T18:06:34Z DEBUG add: 'organizationalUnit' to objectClass, current value ['top'] 2025-05-07T18:06:34Z DEBUG add: updated value ['top', 'organizationalUnit'] 2025-05-07T18:06:34Z DEBUG add: 'profiles' to ou, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['profiles'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: ou=profile,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG organizationalUnit 2025-05-07T18:06:34Z DEBUG ou: 2025-05-07T18:06:34Z DEBUG profiles 2025-05-07T18:06:34Z DEBUG New entry: cn=default,ou=profile,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=default,ou=profile,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG ObjectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG DUAConfigProfile 2025-05-07T18:06:34Z DEBUG defaultServerList: 2025-05-07T18:06:34Z DEBUG master.ufreeipa.test 2025-05-07T18:06:34Z DEBUG defaultSearchBase: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG authenticationMethod: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG searchTimeLimit: 2025-05-07T18:06:34Z DEBUG 15 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG default 2025-05-07T18:06:34Z DEBUG serviceSearchDescriptor: 2025-05-07T18:06:34Z DEBUG passwd:cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG group:cn=groups,cn=compat,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG bindTimeLimit: 2025-05-07T18:06:34Z DEBUG 5 2025-05-07T18:06:34Z DEBUG objectClassMap: 2025-05-07T18:06:34Z DEBUG shadow:shadowAccount=posixAccount 2025-05-07T18:06:34Z DEBUG followReferrals: 2025-05-07T18:06:34Z DEBUG TRUE 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=default,ou=profile,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG ObjectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG DUAConfigProfile 2025-05-07T18:06:34Z DEBUG defaultServerList: 2025-05-07T18:06:34Z DEBUG master.ufreeipa.test 2025-05-07T18:06:34Z DEBUG defaultSearchBase: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG authenticationMethod: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG searchTimeLimit: 2025-05-07T18:06:34Z DEBUG 15 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG default 2025-05-07T18:06:34Z DEBUG serviceSearchDescriptor: 2025-05-07T18:06:34Z DEBUG passwd:cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG group:cn=groups,cn=compat,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG bindTimeLimit: 2025-05-07T18:06:34Z DEBUG 5 2025-05-07T18:06:34Z DEBUG objectClassMap: 2025-05-07T18:06:34Z DEBUG shadow:shadowAccount=posixAccount 2025-05-07T18:06:34Z DEBUG followReferrals: 2025-05-07T18:06:34Z DEBUG TRUE 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-nss_ldap.update 0.077 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/20-replication.update' 2025-05-07T18:06:34Z DEBUG New entry: cn=replication,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=replication,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG nsDS5Replica 2025-05-07T18:06:34Z DEBUG nsDS5ReplicaId: 2025-05-07T18:06:34Z DEBUG 3 2025-05-07T18:06:34Z DEBUG nsDS5ReplicaRoot: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=replication,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG nsDS5Replica 2025-05-07T18:06:34Z DEBUG nsDS5ReplicaId: 2025-05-07T18:06:34Z DEBUG 3 2025-05-07T18:06:34Z DEBUG nsDS5ReplicaRoot: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG New entry: cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG replication managers 2025-05-07T18:06:34Z DEBUG add: 'krbprincipalname=ldap/master.ufreeipa.test@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['krbprincipalname=ldap/master.ufreeipa.test@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG replication managers 2025-05-07T18:06:34Z DEBUG member: 2025-05-07T18:06:34Z DEBUG krbprincipalname=ldap/master.ufreeipa.test@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG topology 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG topology 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=domain,cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG iparepltopoconf 2025-05-07T18:06:34Z DEBUG ipaReplTopoConfRoot: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsDS5ReplicatedAttributeList: 2025-05-07T18:06:34Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime 2025-05-07T18:06:34Z DEBUG nsDS5ReplicatedAttributeListTotal: 2025-05-07T18:06:34Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime 2025-05-07T18:06:34Z DEBUG nsds5ReplicaStripAttrs: 2025-05-07T18:06:34Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG domain 2025-05-07T18:06:34Z DEBUG add: '(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime' to nsDS5ReplicatedAttributeList, current value ['(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime'] 2025-05-07T18:06:34Z DEBUG add: updated value ['(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime'] 2025-05-07T18:06:34Z DEBUG add: '(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime' to nsDS5ReplicatedAttributeListTotal, current value ['(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime'] 2025-05-07T18:06:34Z DEBUG add: updated value ['(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime'] 2025-05-07T18:06:34Z DEBUG add: 'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp' to nsds5ReplicaStripAttrs, current value ['modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2025-05-07T18:06:34Z DEBUG add: updated value ['modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG iparepltopoconf 2025-05-07T18:06:34Z DEBUG ipaReplTopoConfRoot: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsDS5ReplicatedAttributeList: 2025-05-07T18:06:34Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime 2025-05-07T18:06:34Z DEBUG nsDS5ReplicatedAttributeListTotal: 2025-05-07T18:06:34Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime 2025-05-07T18:06:34Z DEBUG nsds5ReplicaStripAttrs: 2025-05-07T18:06:34Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG domain 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Deleting entry cn=realm,cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG cn=realm,cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test did not exist:no such entry 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG ipaReplTopoManagedServer 2025-05-07T18:06:34Z DEBUG ipaConfigObject 2025-05-07T18:06:34Z DEBUG ipaSupportedDomainLevelConfig 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG master.ufreeipa.test 2025-05-07T18:06:34Z DEBUG ipaReplTopoManagedSuffix: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG ipaMinDomainLevel: 2025-05-07T18:06:34Z DEBUG 1 2025-05-07T18:06:34Z DEBUG ipaMaxDomainLevel: 2025-05-07T18:06:34Z DEBUG 1 2025-05-07T18:06:34Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2025-05-07T18:06:34Z DEBUG add: updated value ['top', 'nsContainer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig', 'ipaReplTopoManagedServer'] 2025-05-07T18:06:34Z DEBUG add: 'dc=ufreeipa,dc=test' to ipaReplTopoManagedSuffix, current value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG ipaConfigObject 2025-05-07T18:06:34Z DEBUG ipaSupportedDomainLevelConfig 2025-05-07T18:06:34Z DEBUG ipaReplTopoManagedServer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG master.ufreeipa.test 2025-05-07T18:06:34Z DEBUG ipaReplTopoManagedSuffix: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG ipaMinDomainLevel: 2025-05-07T18:06:34Z DEBUG 1 2025-05-07T18:06:34Z DEBUG ipaMaxDomainLevel: 2025-05-07T18:06:34Z DEBUG 1 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=IPA Topology Configuration,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG IPA Topology Configuration 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:34Z DEBUG ldbm database 2025-05-07T18:06:34Z DEBUG Multisupplier Replication Plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG ipa-topology-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG ipa-topology-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG ipa_topo_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libtopology 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG object 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG freeipa 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 1.0 2025-05-07T18:06:34Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2025-05-07T18:06:34Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-topo-plugin-shared-config-base: 2025-05-07T18:06:34Z DEBUG cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG o=ipaca 2025-05-07T18:06:34Z DEBUG nsslapd-topo-plugin-startup-delay: 2025-05-07T18:06:34Z DEBUG 20 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG IPA Topology Configuration 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:34Z DEBUG ldbm database 2025-05-07T18:06:34Z DEBUG Multisupplier Replication Plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG ipa-topology-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG ipa-topology-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG ipa_topo_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libtopology 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG object 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG freeipa 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 1.0 2025-05-07T18:06:34Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2025-05-07T18:06:34Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-topo-plugin-shared-config-base: 2025-05-07T18:06:34Z DEBUG cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG o=ipaca 2025-05-07T18:06:34Z DEBUG nsslapd-topo-plugin-startup-delay: 2025-05-07T18:06:34Z DEBUG 20 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-replication.update 0.101 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/20-sslciphers.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=encryption,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=encryption,cn=config 2025-05-07T18:06:34Z DEBUG CACertExtractFile: 2025-05-07T18:06:34Z DEBUG /tmp/slapd-UFREEIPA-TEST/UFREEIPA.TEST20IPA20CA.pem 2025-05-07T18:06:34Z DEBUG allowWeakCipher: 2025-05-07T18:06:34Z DEBUG off 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG encryption 2025-05-07T18:06:34Z DEBUG nsSSL3Ciphers: 2025-05-07T18:06:34Z DEBUG default 2025-05-07T18:06:34Z DEBUG nsSSLClientAuth: 2025-05-07T18:06:34Z DEBUG allowed 2025-05-07T18:06:34Z DEBUG nsSSLSessionTimeout: 2025-05-07T18:06:34Z DEBUG 0 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsEncryptionConfig 2025-05-07T18:06:34Z DEBUG nsSSLSupportedCiphers: 2025-05-07T18:06:34Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2025-05-07T18:06:34Z DEBUG only: set nsSSL3Ciphers to 'default', current value ['default'] 2025-05-07T18:06:34Z DEBUG only: updated value ['default'] 2025-05-07T18:06:34Z DEBUG addifnew: 'off' to allowWeakCipher, current value ['off'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=encryption,cn=config 2025-05-07T18:06:34Z DEBUG CACertExtractFile: 2025-05-07T18:06:34Z DEBUG /tmp/slapd-UFREEIPA-TEST/UFREEIPA.TEST20IPA20CA.pem 2025-05-07T18:06:34Z DEBUG allowWeakCipher: 2025-05-07T18:06:34Z DEBUG off 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG encryption 2025-05-07T18:06:34Z DEBUG nsSSL3Ciphers: 2025-05-07T18:06:34Z DEBUG default 2025-05-07T18:06:34Z DEBUG nsSSLClientAuth: 2025-05-07T18:06:34Z DEBUG allowed 2025-05-07T18:06:34Z DEBUG nsSSLSessionTimeout: 2025-05-07T18:06:34Z DEBUG 0 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsEncryptionConfig 2025-05-07T18:06:34Z DEBUG nsSSLSupportedCiphers: 2025-05-07T18:06:34Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2025-05-07T18:06:34Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2025-05-07T18:06:34Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2025-05-07T18:06:34Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-sslciphers.update 0.009 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/20-syncrepl.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=Retro Changelog Plugin,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Retro Changelog Plugin 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:34Z DEBUG Class of Service 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG off 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG retrocl_plugin_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libretrocl-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG object 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:34Z DEBUG 25 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value ['off'] 2025-05-07T18:06:34Z DEBUG only: updated value ['on'] 2025-05-07T18:06:34Z DEBUG add: 'nsuniqueid:targetUniqueId' to nsslapd-attribute, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['nsuniqueid:targetUniqueId'] 2025-05-07T18:06:34Z DEBUG add: '2d' to nsslapd-changelogmaxage, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['2d'] 2025-05-07T18:06:34Z DEBUG add: 'cn=dns,dc=ufreeipa,dc=test' to nsslapd-include-suffix, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['cn=dns,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Retro Changelog Plugin 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:34Z DEBUG Class of Service 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG retrocl_plugin_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libretrocl-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG object 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:34Z DEBUG 25 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG nsslapd-attribute: 2025-05-07T18:06:34Z DEBUG nsuniqueid:targetUniqueId 2025-05-07T18:06:34Z DEBUG nsslapd-changelogmaxage: 2025-05-07T18:06:34Z DEBUG 2d 2025-05-07T18:06:34Z DEBUG nsslapd-include-suffix: 2025-05-07T18:06:34Z DEBUG cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [(2, 'nsslapd-include-suffix', ['cn=dns,dc=ufreeipa,dc=test']), (2, 'nsslapd-attribute', ['nsuniqueid:targetUniqueId']), (2, 'nsslapd-changelogmaxage', ['2d']), (2, 'nsslapd-pluginEnabled', ['on'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(2, 'nsslapd-include-suffix', [b'cn=dns,dc=ufreeipa,dc=test']), (2, 'nsslapd-attribute', [b'nsuniqueid:targetUniqueId']), (2, 'nsslapd-changelogmaxage', [b'2d']), (2, 'nsslapd-pluginEnabled', [b'on'])] 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG MemberOf Plugin 2025-05-07T18:06:34Z DEBUG memberofattr: 2025-05-07T18:06:34Z DEBUG memberOf 2025-05-07T18:06:34Z DEBUG memberofgroupattr: 2025-05-07T18:06:34Z DEBUG member 2025-05-07T18:06:34Z DEBUG memberUser 2025-05-07T18:06:34Z DEBUG memberHost 2025-05-07T18:06:34Z DEBUG ipaOwner 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG memberof plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG memberof 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG memberof_postop_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libmemberof-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG betxnpostoperation 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG add: 'dc=ufreeipa,dc=test' to memberofentryscope, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG add: 'cn=compat,dc=ufreeipa,dc=test' to memberofentryscopeexcludesubtree, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['cn=compat,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG add: 'cn=provisioning,dc=ufreeipa,dc=test' to memberofentryscopeexcludesubtree, current value ['cn=compat,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG add: updated value ['cn=compat,dc=ufreeipa,dc=test', 'cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to memberofentryscopeexcludesubtree, current value ['cn=compat,dc=ufreeipa,dc=test', 'cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG add: updated value ['cn=compat,dc=ufreeipa,dc=test', 'cn=provisioning,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG MemberOf Plugin 2025-05-07T18:06:34Z DEBUG memberofattr: 2025-05-07T18:06:34Z DEBUG memberOf 2025-05-07T18:06:34Z DEBUG memberofgroupattr: 2025-05-07T18:06:34Z DEBUG member 2025-05-07T18:06:34Z DEBUG memberUser 2025-05-07T18:06:34Z DEBUG memberHost 2025-05-07T18:06:34Z DEBUG ipaOwner 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG memberof plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG memberof 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG memberof_postop_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libmemberof-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG betxnpostoperation 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG memberofentryscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG memberofentryscopeexcludesubtree: 2025-05-07T18:06:34Z DEBUG cn=compat,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [(2, 'memberofentryscope', ['dc=ufreeipa,dc=test']), (2, 'memberofentryscopeexcludesubtree', ['cn=compat,dc=ufreeipa,dc=test', 'cn=provisioning,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(2, 'memberofentryscope', [b'dc=ufreeipa,dc=test']), (2, 'memberofentryscopeexcludesubtree', [b'cn=compat,dc=ufreeipa,dc=test', b'cn=provisioning,dc=ufreeipa,dc=test', b'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG referential integrity postoperation 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG referential integrity plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG referint 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG referint_postop_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libreferint-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG betxnpostoperation 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:34Z DEBUG 40 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG referint-logfile: 2025-05-07T18:06:34Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/referint 2025-05-07T18:06:34Z DEBUG referint-membership-attr: 2025-05-07T18:06:34Z DEBUG member 2025-05-07T18:06:34Z DEBUG uniquemember 2025-05-07T18:06:34Z DEBUG owner 2025-05-07T18:06:34Z DEBUG seeAlso 2025-05-07T18:06:34Z DEBUG referint-update-delay: 2025-05-07T18:06:34Z DEBUG 0 2025-05-07T18:06:34Z DEBUG add: 'dc=ufreeipa,dc=test' to nsslapd-plugincontainerscope, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG add: 'dc=ufreeipa,dc=test' to nsslapd-pluginentryscope, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG add: 'cn=provisioning,dc=ufreeipa,dc=test' to nsslapd-pluginExcludeEntryScope, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG referential integrity postoperation 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG referential integrity plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG referint 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG referint_postop_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libreferint-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG betxnpostoperation 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:34Z DEBUG 40 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG referint-logfile: 2025-05-07T18:06:34Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/referint 2025-05-07T18:06:34Z DEBUG referint-membership-attr: 2025-05-07T18:06:34Z DEBUG member 2025-05-07T18:06:34Z DEBUG uniquemember 2025-05-07T18:06:34Z DEBUG owner 2025-05-07T18:06:34Z DEBUG seeAlso 2025-05-07T18:06:34Z DEBUG referint-update-delay: 2025-05-07T18:06:34Z DEBUG 0 2025-05-07T18:06:34Z DEBUG nsslapd-plugincontainerscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-pluginentryscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-pluginExcludeEntryScope: 2025-05-07T18:06:34Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [(2, 'nsslapd-plugincontainerscope', ['dc=ufreeipa,dc=test']), (2, 'nsslapd-pluginExcludeEntryScope', ['cn=provisioning,dc=ufreeipa,dc=test']), (2, 'nsslapd-pluginentryscope', ['dc=ufreeipa,dc=test'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(2, 'nsslapd-plugincontainerscope', [b'dc=ufreeipa,dc=test']), (2, 'nsslapd-pluginExcludeEntryScope', [b'cn=provisioning,dc=ufreeipa,dc=test']), (2, 'nsslapd-pluginentryscope', [b'dc=ufreeipa,dc=test'])] 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=Content Synchronization,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Content Synchronization 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:34Z DEBUG Retro Changelog Plugin 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG off 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG sync_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libcontentsync-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG object 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value ['off'] 2025-05-07T18:06:34Z DEBUG only: updated value ['on'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Content Synchronization 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-named: 2025-05-07T18:06:34Z DEBUG Retro Changelog Plugin 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG sync_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libcontentsync-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG object 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG none 2025-05-07T18:06:34Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG [(2, 'nsslapd-pluginEnabled', ['on'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(2, 'nsslapd-pluginEnabled', [b'on'])] 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG IPA Unique IDs 2025-05-07T18:06:34Z DEBUG ipauuidattr: 2025-05-07T18:06:34Z DEBUG ipaUniqueID 2025-05-07T18:06:34Z DEBUG ipauuidenforce: 2025-05-07T18:06:34Z DEBUG TRUE 2025-05-07T18:06:34Z DEBUG ipauuidfilter: 2025-05-07T18:06:34Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2025-05-07T18:06:34Z DEBUG ipauuidmagicregen: 2025-05-07T18:06:34Z DEBUG autogenerate 2025-05-07T18:06:34Z DEBUG ipauuidscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG add: 'cn=provisioning,dc=ufreeipa,dc=test' to ipaUuidExcludeSubtree, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['cn=provisioning,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG IPA Unique IDs 2025-05-07T18:06:34Z DEBUG ipauuidattr: 2025-05-07T18:06:34Z DEBUG ipaUniqueID 2025-05-07T18:06:34Z DEBUG ipauuidenforce: 2025-05-07T18:06:34Z DEBUG TRUE 2025-05-07T18:06:34Z DEBUG ipauuidfilter: 2025-05-07T18:06:34Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2025-05-07T18:06:34Z DEBUG ipauuidmagicregen: 2025-05-07T18:06:34Z DEBUG autogenerate 2025-05-07T18:06:34Z DEBUG ipauuidscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG ipaUuidExcludeSubtree: 2025-05-07T18:06:34Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [(2, 'ipaUuidExcludeSubtree', ['cn=provisioning,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(2, 'ipaUuidExcludeSubtree', [b'cn=provisioning,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-syncrepl.update 0.143 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/20-user_private_groups.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG mepTemplateEntry 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG UPG Template 2025-05-07T18:06:34Z DEBUG mepRDNAttr: 2025-05-07T18:06:34Z DEBUG cn 2025-05-07T18:06:34Z DEBUG mepStaticAttr: 2025-05-07T18:06:34Z DEBUG objectclass: posixgroup 2025-05-07T18:06:34Z DEBUG objectclass: ipaobject 2025-05-07T18:06:34Z DEBUG ipaUniqueId: autogenerate 2025-05-07T18:06:34Z DEBUG mepMappedAttr: 2025-05-07T18:06:34Z DEBUG cn: $uid 2025-05-07T18:06:34Z DEBUG gidNumber: $uidNumber 2025-05-07T18:06:34Z DEBUG description: User private group for $uid 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG mepTemplateEntry 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG UPG Template 2025-05-07T18:06:34Z DEBUG mepRDNAttr: 2025-05-07T18:06:34Z DEBUG cn 2025-05-07T18:06:34Z DEBUG mepStaticAttr: 2025-05-07T18:06:34Z DEBUG objectclass: posixgroup 2025-05-07T18:06:34Z DEBUG objectclass: ipaobject 2025-05-07T18:06:34Z DEBUG ipaUniqueId: autogenerate 2025-05-07T18:06:34Z DEBUG mepMappedAttr: 2025-05-07T18:06:34Z DEBUG cn: $uid 2025-05-07T18:06:34Z DEBUG gidNumber: $uidNumber 2025-05-07T18:06:34Z DEBUG description: User private group for $uid 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG UPG Definition 2025-05-07T18:06:34Z DEBUG originScope: 2025-05-07T18:06:34Z DEBUG cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG originFilter: 2025-05-07T18:06:34Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2025-05-07T18:06:34Z DEBUG managedBase: 2025-05-07T18:06:34Z DEBUG cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG managedTemplate: 2025-05-07T18:06:34Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG UPG Definition 2025-05-07T18:06:34Z DEBUG originScope: 2025-05-07T18:06:34Z DEBUG cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG originFilter: 2025-05-07T18:06:34Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2025-05-07T18:06:34Z DEBUG managedBase: 2025-05-07T18:06:34Z DEBUG cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG managedTemplate: 2025-05-07T18:06:34Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG UPG Definition 2025-05-07T18:06:34Z DEBUG originScope: 2025-05-07T18:06:34Z DEBUG cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG originFilter: 2025-05-07T18:06:34Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2025-05-07T18:06:34Z DEBUG managedBase: 2025-05-07T18:06:34Z DEBUG cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG managedTemplate: 2025-05-07T18:06:34Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG replace: objectclass=posixAccount not found, skipping 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG UPG Definition 2025-05-07T18:06:34Z DEBUG originScope: 2025-05-07T18:06:34Z DEBUG cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG originFilter: 2025-05-07T18:06:34Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2025-05-07T18:06:34Z DEBUG managedBase: 2025-05-07T18:06:34Z DEBUG cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG managedTemplate: 2025-05-07T18:06:34Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-user_private_groups.update 0.022 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/20-uuid.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG IPK11 Unique IDs 2025-05-07T18:06:34Z DEBUG ipauuidattr: 2025-05-07T18:06:34Z DEBUG ipk11UniqueID 2025-05-07T18:06:34Z DEBUG ipauuidenforce: 2025-05-07T18:06:34Z DEBUG FALSE 2025-05-07T18:06:34Z DEBUG ipauuidfilter: 2025-05-07T18:06:34Z DEBUG (objectclass=ipk11Object) 2025-05-07T18:06:34Z DEBUG ipauuidmagicregen: 2025-05-07T18:06:34Z DEBUG autogenerate 2025-05-07T18:06:34Z DEBUG ipauuidscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG IPK11 Unique IDs 2025-05-07T18:06:34Z DEBUG ipauuidattr: 2025-05-07T18:06:34Z DEBUG ipk11UniqueID 2025-05-07T18:06:34Z DEBUG ipauuidenforce: 2025-05-07T18:06:34Z DEBUG FALSE 2025-05-07T18:06:34Z DEBUG ipauuidfilter: 2025-05-07T18:06:34Z DEBUG (objectclass=ipk11Object) 2025-05-07T18:06:34Z DEBUG ipauuidmagicregen: 2025-05-07T18:06:34Z DEBUG autogenerate 2025-05-07T18:06:34Z DEBUG ipauuidscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-uuid.update 0.013 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/20-whoami.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG whoami 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG whoami extended operation plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG whoami-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG whoami_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libwhoami-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG extendedop 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG whoami 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG whoami extended operation plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG whoami-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG whoami_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libwhoami-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG extendedop 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-whoami.update 0.027 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/21-ca_renewal_container.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ca_renewal 2025-05-07T18:06:34Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2025-05-07T18:06:34Z DEBUG add: updated value ['nsContainer', 'top'] 2025-05-07T18:06:34Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2025-05-07T18:06:34Z DEBUG add: updated value ['top', 'nsContainer'] 2025-05-07T18:06:34Z DEBUG add: 'ca_renewal' to cn, current value ['ca_renewal'] 2025-05-07T18:06:34Z DEBUG add: updated value ['ca_renewal'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ca_renewal 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-ca_renewal_container.update 0.007 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/21-certstore_container.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG certificates 2025-05-07T18:06:34Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2025-05-07T18:06:34Z DEBUG add: updated value ['nsContainer', 'top'] 2025-05-07T18:06:34Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2025-05-07T18:06:34Z DEBUG add: updated value ['top', 'nsContainer'] 2025-05-07T18:06:34Z DEBUG add: 'certificates' to cn, current value ['certificates'] 2025-05-07T18:06:34Z DEBUG add: updated value ['certificates'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG certificates 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-certstore_container.update 0.007 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/21-replicas_container.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG replicas 2025-05-07T18:06:34Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2025-05-07T18:06:34Z DEBUG add: updated value ['nsContainer', 'top'] 2025-05-07T18:06:34Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2025-05-07T18:06:34Z DEBUG add: updated value ['top', 'nsContainer'] 2025-05-07T18:06:34Z DEBUG add: 'replicas' to cn, current value ['replicas'] 2025-05-07T18:06:34Z DEBUG add: updated value ['replicas'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG replicas 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-replicas_container.update 0.006 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/25-referint.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG referential integrity postoperation 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG referential integrity plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG referint 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG referint_postop_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libreferint-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG betxnpostoperation 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:34Z DEBUG 40 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG referint-logfile: 2025-05-07T18:06:34Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/referint 2025-05-07T18:06:34Z DEBUG referint-membership-attr: 2025-05-07T18:06:34Z DEBUG member 2025-05-07T18:06:34Z DEBUG uniquemember 2025-05-07T18:06:34Z DEBUG owner 2025-05-07T18:06:34Z DEBUG seeAlso 2025-05-07T18:06:34Z DEBUG referint-update-delay: 2025-05-07T18:06:34Z DEBUG 0 2025-05-07T18:06:34Z DEBUG nsslapd-plugincontainerscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-pluginexcludeentryscope: 2025-05-07T18:06:34Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-pluginentryscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG add: 'manager' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager'] 2025-05-07T18:06:34Z DEBUG add: 'secretary' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary'] 2025-05-07T18:06:34Z DEBUG add: 'memberuser' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser'] 2025-05-07T18:06:34Z DEBUG add: 'memberhost' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost'] 2025-05-07T18:06:34Z DEBUG add: 'sourcehost' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost'] 2025-05-07T18:06:34Z DEBUG add: 'memberservice' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice'] 2025-05-07T18:06:34Z DEBUG add: 'managedby' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby'] 2025-05-07T18:06:34Z DEBUG add: 'memberallowcmd' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd'] 2025-05-07T18:06:34Z DEBUG add: 'memberdenycmd' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd'] 2025-05-07T18:06:34Z DEBUG add: 'ipasudorunas' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas'] 2025-05-07T18:06:34Z DEBUG add: 'ipasudorunasgroup' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup'] 2025-05-07T18:06:34Z DEBUG add: 'ipatokenradiusconfiglink' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink'] 2025-05-07T18:06:34Z DEBUG add: 'ipaassignedidview' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview'] 2025-05-07T18:06:34Z DEBUG add: 'ipaallowedtarget' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget'] 2025-05-07T18:06:34Z DEBUG add: 'ipamemberca' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca'] 2025-05-07T18:06:34Z DEBUG add: 'ipamembercertprofile' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile'] 2025-05-07T18:06:34Z DEBUG add: 'ipalocation' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation'] 2025-05-07T18:06:34Z DEBUG add: 'membermanager' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager'] 2025-05-07T18:06:34Z DEBUG add: 'ipaowner' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager', 'ipaowner'] 2025-05-07T18:06:34Z DEBUG add: 'ipaidpconfiglink' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager', 'ipaowner'] 2025-05-07T18:06:34Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager', 'ipaowner', 'ipaidpconfiglink'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG referential integrity postoperation 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG referential integrity plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG referint 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG referint_postop_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libreferint-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG betxnpostoperation 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:34Z DEBUG 40 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG referint-logfile: 2025-05-07T18:06:34Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/referint 2025-05-07T18:06:34Z DEBUG referint-membership-attr: 2025-05-07T18:06:34Z DEBUG member 2025-05-07T18:06:34Z DEBUG uniquemember 2025-05-07T18:06:34Z DEBUG owner 2025-05-07T18:06:34Z DEBUG seeAlso 2025-05-07T18:06:34Z DEBUG manager 2025-05-07T18:06:34Z DEBUG secretary 2025-05-07T18:06:34Z DEBUG memberuser 2025-05-07T18:06:34Z DEBUG memberhost 2025-05-07T18:06:34Z DEBUG sourcehost 2025-05-07T18:06:34Z DEBUG memberservice 2025-05-07T18:06:34Z DEBUG managedby 2025-05-07T18:06:34Z DEBUG memberallowcmd 2025-05-07T18:06:34Z DEBUG memberdenycmd 2025-05-07T18:06:34Z DEBUG ipasudorunas 2025-05-07T18:06:34Z DEBUG ipasudorunasgroup 2025-05-07T18:06:34Z DEBUG ipatokenradiusconfiglink 2025-05-07T18:06:34Z DEBUG ipaassignedidview 2025-05-07T18:06:34Z DEBUG ipaallowedtarget 2025-05-07T18:06:34Z DEBUG ipamemberca 2025-05-07T18:06:34Z DEBUG ipamembercertprofile 2025-05-07T18:06:34Z DEBUG ipalocation 2025-05-07T18:06:34Z DEBUG membermanager 2025-05-07T18:06:34Z DEBUG ipaowner 2025-05-07T18:06:34Z DEBUG ipaidpconfiglink 2025-05-07T18:06:34Z DEBUG referint-update-delay: 2025-05-07T18:06:34Z DEBUG 0 2025-05-07T18:06:34Z DEBUG nsslapd-plugincontainerscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-pluginexcludeentryscope: 2025-05-07T18:06:34Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-pluginentryscope: 2025-05-07T18:06:34Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [(0, 'referint-membership-attr', ['manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager', 'ipaowner', 'ipaidpconfiglink'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(0, 'referint-membership-attr', [b'manager', b'secretary', b'memberuser', b'memberhost', b'sourcehost', b'memberservice', b'managedby', b'memberallowcmd', b'memberdenycmd', b'ipasudorunas', b'ipasudorunasgroup', b'ipatokenradiusconfiglink', b'ipaassignedidview', b'ipaallowedtarget', b'ipamemberca', b'ipamembercertprofile', b'ipalocation', b'membermanager', b'ipaowner', b'ipaidpconfiglink'])] 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/25-referint.update 0.032 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/30-ipservices.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=ipservices,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=ipservices,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipservices 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=ipservices,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipservices 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-ipservices.update 0.008 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/30-provisioning.update' 2025-05-07T18:06:34Z DEBUG New entry: cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG provisioning 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG provisioning 2025-05-07T18:06:34Z DEBUG New entry: cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG accounts 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG accounts 2025-05-07T18:06:34Z DEBUG New entry: cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG staged users 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG staged users 2025-05-07T18:06:34Z DEBUG New entry: cn=deleted users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG deleted users 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectclass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG deleted users 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG staged users 2025-05-07T18:06:34Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value [] 2025-05-07T18:06:34Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:34Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG staged users 2025-05-07T18:06:34Z DEBUG aci: 2025-05-07T18:06:34Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG [(2, 'aci', ['(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=deleted users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG deleted users 2025-05-07T18:06:34Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value [] 2025-05-07T18:06:34Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:34Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:34Z DEBUG add: '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)' to aci, current value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:34Z DEBUG add: updated value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG deleted users 2025-05-07T18:06:34Z DEBUG aci: 2025-05-07T18:06:34Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2025-05-07T18:06:34Z DEBUG [(2, 'aci', ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', b'(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'])] 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG New entry: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cosSuperDefinition 2025-05-07T18:06:34Z DEBUG cosPointerDefinition 2025-05-07T18:06:34Z DEBUG ldapSubEntry 2025-05-07T18:06:34Z DEBUG costemplatedn: 2025-05-07T18:06:34Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG cosAttribute: 2025-05-07T18:06:34Z DEBUG nsaccountlock operational 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG provisioning accounts lock 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cosSuperDefinition 2025-05-07T18:06:34Z DEBUG cosPointerDefinition 2025-05-07T18:06:34Z DEBUG ldapSubEntry 2025-05-07T18:06:34Z DEBUG costemplatedn: 2025-05-07T18:06:34Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG cosAttribute: 2025-05-07T18:06:34Z DEBUG nsaccountlock operational 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG provisioning accounts lock 2025-05-07T18:06:34Z DEBUG New entry: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG cosTemplate 2025-05-07T18:06:34Z DEBUG cosPriority: 2025-05-07T18:06:34Z DEBUG 1 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Inactivation cos template 2025-05-07T18:06:34Z DEBUG nsAccountLock: 2025-05-07T18:06:34Z DEBUG true 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG cosTemplate 2025-05-07T18:06:34Z DEBUG cosPriority: 2025-05-07T18:06:34Z DEBUG 1 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Inactivation cos template 2025-05-07T18:06:34Z DEBUG nsAccountLock: 2025-05-07T18:06:34Z DEBUG true 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-provisioning.update 0.286 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/30-s4u2proxy.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG s4u2proxy 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG s4u2proxy 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG ipaKrb5DelegationACL 2025-05-07T18:06:34Z DEBUG groupOfPrincipals 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipa-http-delegation 2025-05-07T18:06:34Z DEBUG memberPrincipal: 2025-05-07T18:06:34Z DEBUG HTTP/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:34Z DEBUG ipaAllowedTarget: 2025-05-07T18:06:34Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG ipaKrb5DelegationACL 2025-05-07T18:06:34Z DEBUG groupOfPrincipals 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipa-http-delegation 2025-05-07T18:06:34Z DEBUG memberPrincipal: 2025-05-07T18:06:34Z DEBUG HTTP/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:34Z DEBUG ipaAllowedTarget: 2025-05-07T18:06:34Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG groupOfPrincipals 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipa-ldap-delegation-targets 2025-05-07T18:06:34Z DEBUG memberPrincipal: 2025-05-07T18:06:34Z DEBUG ldap/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG groupOfPrincipals 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipa-ldap-delegation-targets 2025-05-07T18:06:34Z DEBUG memberPrincipal: 2025-05-07T18:06:34Z DEBUG ldap/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG ipaKrb5DelegationACL 2025-05-07T18:06:34Z DEBUG groupOfPrincipals 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipa-http-delegation 2025-05-07T18:06:34Z DEBUG memberPrincipal: 2025-05-07T18:06:34Z DEBUG HTTP/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:34Z DEBUG ipaAllowedTarget: 2025-05-07T18:06:34Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG add: 'HTTP/master.ufreeipa.test@UFREEIPA.TEST' to memberPrincipal, current value ['HTTP/master.ufreeipa.test@UFREEIPA.TEST'] 2025-05-07T18:06:34Z DEBUG add: updated value ['HTTP/master.ufreeipa.test@UFREEIPA.TEST'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG ipaKrb5DelegationACL 2025-05-07T18:06:34Z DEBUG groupOfPrincipals 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipa-http-delegation 2025-05-07T18:06:34Z DEBUG memberPrincipal: 2025-05-07T18:06:34Z DEBUG HTTP/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:34Z DEBUG ipaAllowedTarget: 2025-05-07T18:06:34Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG groupOfPrincipals 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipa-ldap-delegation-targets 2025-05-07T18:06:34Z DEBUG memberPrincipal: 2025-05-07T18:06:34Z DEBUG ldap/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:34Z DEBUG add: 'ldap/master.ufreeipa.test@UFREEIPA.TEST' to memberPrincipal, current value ['ldap/master.ufreeipa.test@UFREEIPA.TEST'] 2025-05-07T18:06:34Z DEBUG add: updated value ['ldap/master.ufreeipa.test@UFREEIPA.TEST'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG groupOfPrincipals 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ipa-ldap-delegation-targets 2025-05-07T18:06:34Z DEBUG memberPrincipal: 2025-05-07T18:06:34Z DEBUG ldap/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-s4u2proxy.update 0.061 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/37-locations.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=locations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=locations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG locations 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=locations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG locations 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/37-locations.update 0.008 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/40-automember.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG automemberprocessmodifyops: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Auto Membership Plugin 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:34Z DEBUG cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG Auto Membership plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG Auto Membership 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG automember_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libautomember-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG betxnpreoperation 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG addifnew: 'cn=automember,cn=etc,dc=ufreeipa,dc=test' to nsslapd-pluginConfigArea, current value ['cn=automember,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2025-05-07T18:06:34Z DEBUG automemberprocessmodifyops: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Auto Membership Plugin 2025-05-07T18:06:34Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:34Z DEBUG database 2025-05-07T18:06:34Z DEBUG nsslapd-pluginConfigArea: 2025-05-07T18:06:34Z DEBUG cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:34Z DEBUG Auto Membership plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:34Z DEBUG on 2025-05-07T18:06:34Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:34Z DEBUG Auto Membership 2025-05-07T18:06:34Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:34Z DEBUG automember_init 2025-05-07T18:06:34Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:34Z DEBUG libautomember-plugin 2025-05-07T18:06:34Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:34Z DEBUG betxnpreoperation 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:34Z DEBUG 389 Project 2025-05-07T18:06:34Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:34Z DEBUG 3.1.2 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsSlapdPlugin 2025-05-07T18:06:34Z DEBUG extensibleObject 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG automember 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG automember 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=Hostgroup,cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG autoMemberDefinition 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Hostgroup 2025-05-07T18:06:34Z DEBUG autoMemberScope: 2025-05-07T18:06:34Z DEBUG cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG autoMemberFilter: 2025-05-07T18:06:34Z DEBUG objectclass=ipaHost 2025-05-07T18:06:34Z DEBUG autoMemberGroupingAttr: 2025-05-07T18:06:34Z DEBUG member:dn 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG autoMemberDefinition 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Hostgroup 2025-05-07T18:06:34Z DEBUG autoMemberScope: 2025-05-07T18:06:34Z DEBUG cn=computers,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG autoMemberFilter: 2025-05-07T18:06:34Z DEBUG objectclass=ipaHost 2025-05-07T18:06:34Z DEBUG autoMemberGroupingAttr: 2025-05-07T18:06:34Z DEBUG member:dn 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=Group,cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG autoMemberDefinition 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Group 2025-05-07T18:06:34Z DEBUG autoMemberScope: 2025-05-07T18:06:34Z DEBUG cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG autoMemberFilter: 2025-05-07T18:06:34Z DEBUG objectclass=posixAccount 2025-05-07T18:06:34Z DEBUG autoMemberGroupingAttr: 2025-05-07T18:06:34Z DEBUG member:dn 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG autoMemberDefinition 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Group 2025-05-07T18:06:34Z DEBUG autoMemberScope: 2025-05-07T18:06:34Z DEBUG cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG autoMemberFilter: 2025-05-07T18:06:34Z DEBUG objectclass=posixAccount 2025-05-07T18:06:34Z DEBUG autoMemberGroupingAttr: 2025-05-07T18:06:34Z DEBUG member:dn 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-automember.update 0.028 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/40-certprofile.update' 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ca 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG ca 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=certprofiles,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=certprofiles,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG certprofiles 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=certprofiles,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nsContainer 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG certprofiles 2025-05-07T18:06:34Z DEBUG [] 2025-05-07T18:06:34Z DEBUG Updated 0 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-certprofile.update 0.018 sec 2025-05-07T18:06:34Z DEBUG Parsing update file '/usr/share/ipa/updates/40-delegation.update' 2025-05-07T18:06:34Z DEBUG New entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Write IPA Configuration 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG Write IPA Configuration 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Write IPA Configuration 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG Write IPA Configuration 2025-05-07T18:06:34Z DEBUG New entry: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG ipapermission 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Write IPA Configuration 2025-05-07T18:06:34Z DEBUG member: 2025-05-07T18:06:34Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG ipapermission 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Write IPA Configuration 2025-05-07T18:06:34Z DEBUG member: 2025-05-07T18:06:34Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG domain 2025-05-07T18:06:34Z DEBUG pilotObject 2025-05-07T18:06:34Z DEBUG domainRelatedObject 2025-05-07T18:06:34Z DEBUG nisDomainObject 2025-05-07T18:06:34Z DEBUG dc: 2025-05-07T18:06:34Z DEBUG ufreeipa 2025-05-07T18:06:34Z DEBUG info: 2025-05-07T18:06:34Z DEBUG IPA V2.0 2025-05-07T18:06:34Z DEBUG associatedDomain: 2025-05-07T18:06:34Z DEBUG ufreeipa.test 2025-05-07T18:06:34Z DEBUG nisDomain: 2025-05-07T18:06:34Z DEBUG ufreeipa.test 2025-05-07T18:06:34Z DEBUG aci: 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:34Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:34Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:34Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:34Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:34Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:34Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:34Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG add: '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:34Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG domain 2025-05-07T18:06:34Z DEBUG pilotObject 2025-05-07T18:06:34Z DEBUG domainRelatedObject 2025-05-07T18:06:34Z DEBUG nisDomainObject 2025-05-07T18:06:34Z DEBUG dc: 2025-05-07T18:06:34Z DEBUG ufreeipa 2025-05-07T18:06:34Z DEBUG info: 2025-05-07T18:06:34Z DEBUG IPA V2.0 2025-05-07T18:06:34Z DEBUG associatedDomain: 2025-05-07T18:06:34Z DEBUG ufreeipa.test 2025-05-07T18:06:34Z DEBUG nisDomain: 2025-05-07T18:06:34Z DEBUG ufreeipa.test 2025-05-07T18:06:34Z DEBUG aci: 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:34Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:34Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:34Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:34Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:34Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:34Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:34Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:34Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:34Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:34Z DEBUG [(0, 'aci', ['(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:34Z DEBUG Done 2025-05-07T18:06:34Z DEBUG New entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG HBAC Administrator 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG HBAC Administrator 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG HBAC Administrator 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG HBAC Administrator 2025-05-07T18:06:34Z DEBUG New entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Sudo Administrator 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG Sudo Administrator 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Sudo Administrator 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG Sudo Administrator 2025-05-07T18:06:34Z DEBUG New entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Password Policy Administrator 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG Password Policy Administrator 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Password Policy Administrator 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG Password Policy Administrator 2025-05-07T18:06:34Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Initial value 2025-05-07T18:06:34Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Host Enrollment 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG Host Enrollment 2025-05-07T18:06:34Z DEBUG add: 'cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:34Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:34Z DEBUG --------------------------------------------- 2025-05-07T18:06:34Z DEBUG Final value after applying updates 2025-05-07T18:06:34Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG objectClass: 2025-05-07T18:06:34Z DEBUG top 2025-05-07T18:06:34Z DEBUG groupofnames 2025-05-07T18:06:34Z DEBUG nestedgroup 2025-05-07T18:06:34Z DEBUG cn: 2025-05-07T18:06:34Z DEBUG Host Enrollment 2025-05-07T18:06:34Z DEBUG description: 2025-05-07T18:06:34Z DEBUG Host Enrollment 2025-05-07T18:06:34Z DEBUG member: 2025-05-07T18:06:34Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:34Z DEBUG [(2, 'member', ['cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:34Z DEBUG Updated 1 2025-05-07T18:06:34Z DEBUG update_entry modlist [(2, 'member', [b'cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG domain 2025-05-07T18:06:35Z DEBUG pilotObject 2025-05-07T18:06:35Z DEBUG domainRelatedObject 2025-05-07T18:06:35Z DEBUG nisDomainObject 2025-05-07T18:06:35Z DEBUG dc: 2025-05-07T18:06:35Z DEBUG ufreeipa 2025-05-07T18:06:35Z DEBUG info: 2025-05-07T18:06:35Z DEBUG IPA V2.0 2025-05-07T18:06:35Z DEBUG associatedDomain: 2025-05-07T18:06:35Z DEBUG ufreeipa.test 2025-05-07T18:06:35Z DEBUG nisDomain: 2025-05-07T18:06:35Z DEBUG ufreeipa.test 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG domain 2025-05-07T18:06:35Z DEBUG pilotObject 2025-05-07T18:06:35Z DEBUG domainRelatedObject 2025-05-07T18:06:35Z DEBUG nisDomainObject 2025-05-07T18:06:35Z DEBUG dc: 2025-05-07T18:06:35Z DEBUG ufreeipa 2025-05-07T18:06:35Z DEBUG info: 2025-05-07T18:06:35Z DEBUG IPA V2.0 2025-05-07T18:06:35Z DEBUG associatedDomain: 2025-05-07T18:06:35Z DEBUG ufreeipa.test 2025-05-07T18:06:35Z DEBUG nisDomain: 2025-05-07T18:06:35Z DEBUG ufreeipa.test 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG [] 2025-05-07T18:06:35Z DEBUG Updated 0 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG New entry: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG SELinux User Map Administrators 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG SELinux User Map Administrators 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG SELinux User Map Administrators 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG SELinux User Map Administrators 2025-05-07T18:06:35Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG ipa 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG ipa 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Updated 1 2025-05-07T18:06:35Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', b'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG Updating existing entry: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Retrieve Certificates from the CA 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test' to member, current value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test'] 2025-05-07T18:06:35Z DEBUG add: updated value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test'] 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Retrieve Certificates from the CA 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG [(0, 'member', ['cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:35Z DEBUG Updated 1 2025-05-07T18:06:35Z DEBUG update_entry modlist [(0, 'member', [b'cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG Updating existing entry: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Revoke Certificate 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test' to member, current value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test'] 2025-05-07T18:06:35Z DEBUG add: updated value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test'] 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Revoke Certificate 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG [(0, 'member', ['cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:35Z DEBUG Updated 1 2025-05-07T18:06:35Z DEBUG update_entry modlist [(0, 'member', [b'cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG ipa 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG add: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG ipa 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Updated 1 2025-05-07T18:06:35Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG certificates 2025-05-07T18:06:35Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value [] 2025-05-07T18:06:35Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG add: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value [] 2025-05-07T18:06:35Z DEBUG add: updated value ['(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG certificates 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG [(2, 'aci', ['(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Updated 1 2025-05-07T18:06:35Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG New entry: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Automember Task Administrator 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Automember Task Administrator 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Automember Task Administrator 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Automember Task Administrator 2025-05-07T18:06:35Z DEBUG New entry: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Add Automember Rebuild Membership Task 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG ipapermissiontype: 2025-05-07T18:06:35Z DEBUG SYSTEM 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Add Automember Rebuild Membership Task 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG ipapermissiontype: 2025-05-07T18:06:35Z DEBUG SYSTEM 2025-05-07T18:06:35Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=config 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG config 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG extensibleObject 2025-05-07T18:06:35Z DEBUG nsslapdConfig 2025-05-07T18:06:35Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:35Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-betype: 2025-05-07T18:06:35Z DEBUG ldbm database 2025-05-07T18:06:35Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:35Z DEBUG cn=schema 2025-05-07T18:06:35Z DEBUG cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-plugin: 2025-05-07T18:06:35Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 10 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:35Z DEBUG 8192 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-port: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:35Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-localuser: 2025-05-07T18:06:35Z DEBUG dirsrv 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG passwordInHistory: 2025-05-07T18:06:35Z DEBUG 6 2025-05-07T18:06:35Z DEBUG passwordUnlock: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG passwordGraceLimit: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG passwordMustChange: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:35Z DEBUG 100000 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG passwordWarning: 2025-05-07T18:06:35Z DEBUG 86400 2025-05-07T18:06:35Z DEBUG nsslapd-readonly: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:35Z DEBUG 16 2025-05-07T18:06:35Z DEBUG passwordLockout: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-localhost: 2025-05-07T18:06:35Z DEBUG master.ufreeipa.test 2025-05-07T18:06:35Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:35Z DEBUG 10000 2025-05-07T18:06:35Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:35Z DEBUG 40 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG passwordMinLength: 2025-05-07T18:06:35Z DEBUG 8 2025-05-07T18:06:35Z DEBUG passwordMinDigits: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinAlphas: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinUppers: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinLowers: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinSpecials: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMin8bit: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinCategories: 2025-05-07T18:06:35Z DEBUG 3 2025-05-07T18:06:35Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:35Z DEBUG 3 2025-05-07T18:06:35Z DEBUG passwordPalindrome: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordDictCheck: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordDictPath: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG passwordUserAttributes: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG passwordBadWords: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG passwordMaxSequence: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:35Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:35Z DEBUG replication-only 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 500 2025-05-07T18:06:35Z DEBUG passwordMaxFailure: 2025-05-07T18:06:35Z DEBUG 3 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:35Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-security: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordMaxAge: 2025-05-07T18:06:35Z DEBUG 8640000 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG week 2025-05-07T18:06:35Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:35Z DEBUG -1 2025-05-07T18:06:35Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:35Z DEBUG -1 2025-05-07T18:06:35Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:35Z DEBUG -1 2025-05-07T18:06:35Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 2 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:35Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:35Z DEBUG passwordChange: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:35Z DEBUG 256 2025-05-07T18:06:35Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:35Z DEBUG 256 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG week 2025-05-07T18:06:35Z DEBUG nsslapd-securePort: 2025-05-07T18:06:35Z DEBUG 636 2025-05-07T18:06:35Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:35Z DEBUG 3600 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:35Z DEBUG 185 2025-05-07T18:06:35Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG passwordExp: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG day 2025-05-07T18:06:35Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:35Z DEBUG 3600 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:35Z DEBUG 3600 2025-05-07T18:06:35Z DEBUG nsslapd-nagle: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:35Z DEBUG default 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:35Z DEBUG %FT%TZ 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:35Z DEBUG default 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:35Z DEBUG %FT%TZ 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:35Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:35Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:35Z DEBUG cn=Directory Manager 2025-05-07T18:06:35Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:35Z DEBUG uidNumber 2025-05-07T18:06:35Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:35Z DEBUG gidNumber 2025-05-07T18:06:35Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:35Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:35Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:35Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG nsslapd-counters: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 2 2025-05-07T18:06:35Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:35Z DEBUG cn=Directory Manager 2025-05-07T18:06:35Z DEBUG passwordMinAge: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:35Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:35Z DEBUG 209715200 2025-05-07T18:06:35Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:35Z DEBUG 2097152 2025-05-07T18:06:35Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:35Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:35Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:35Z DEBUG 524288 2025-05-07T18:06:35Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:35Z DEBUG allowed 2025-05-07T18:06:35Z DEBUG nsslapd-config: 2025-05-07T18:06:35Z DEBUG cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:35Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:35Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:35Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:35Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:35Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:35Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:35Z DEBUG /tmp 2025-05-07T18:06:35Z DEBUG nsslapd-certdir: 2025-05-07T18:06:35Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:35Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:35Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:35Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:35Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:35Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-rundir: 2025-05-07T18:06:35Z DEBUG /run/dirsrv 2025-05-07T18:06:35Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:35Z DEBUG 300000 2025-05-07T18:06:35Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-localssf: 2025-05-07T18:06:35Z DEBUG 71 2025-05-07T18:06:35Z DEBUG nsslapd-minssf: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:35Z DEBUG next 2025-05-07T18:06:35Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:35Z DEBUG warn 2025-05-07T18:06:35Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:35Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:35Z DEBUG 2097152 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:35Z DEBUG 60 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:35Z DEBUG 20971520 2025-05-07T18:06:35Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:35Z DEBUG nolog 2025-05-07T18:06:35Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:35Z DEBUG 2097152 2025-05-07T18:06:35Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:35Z DEBUG 128 2025-05-07T18:06:35Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:35Z DEBUG -10 2025-05-07T18:06:35Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:35Z DEBUG -10 2025-05-07T18:06:35Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:35Z DEBUG -10 2025-05-07T18:06:35Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:35Z DEBUG -1 2025-05-07T18:06:35Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 2 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG week 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 500 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 10 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG week 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:35Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:35Z DEBUG dirsrv-log 2025-05-07T18:06:35Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:35Z DEBUG none 2025-05-07T18:06:35Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:35Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:35Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:35Z DEBUG process-safe 2025-05-07T18:06:35Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:35Z DEBUG 3600 2025-05-07T18:06:35Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:35Z DEBUG 30 2025-05-07T18:06:35Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:35Z DEBUG 300 2025-05-07T18:06:35Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:35Z DEBUG 300 2025-05-07T18:06:35Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG passwordStorageScheme: 2025-05-07T18:06:35Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:35Z DEBUG passwordAdminDN: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:35Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:35Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2025-05-07T18:06:35Z DEBUG remove: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG add: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2025-05-07T18:06:35Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=config 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG config 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG extensibleObject 2025-05-07T18:06:35Z DEBUG nsslapdConfig 2025-05-07T18:06:35Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:35Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-betype: 2025-05-07T18:06:35Z DEBUG ldbm database 2025-05-07T18:06:35Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:35Z DEBUG cn=schema 2025-05-07T18:06:35Z DEBUG cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-plugin: 2025-05-07T18:06:35Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 10 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:35Z DEBUG 8192 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-port: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:35Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-localuser: 2025-05-07T18:06:35Z DEBUG dirsrv 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG passwordInHistory: 2025-05-07T18:06:35Z DEBUG 6 2025-05-07T18:06:35Z DEBUG passwordUnlock: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG passwordGraceLimit: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG passwordMustChange: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:35Z DEBUG 100000 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG passwordWarning: 2025-05-07T18:06:35Z DEBUG 86400 2025-05-07T18:06:35Z DEBUG nsslapd-readonly: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:35Z DEBUG 16 2025-05-07T18:06:35Z DEBUG passwordLockout: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-localhost: 2025-05-07T18:06:35Z DEBUG master.ufreeipa.test 2025-05-07T18:06:35Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:35Z DEBUG 10000 2025-05-07T18:06:35Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:35Z DEBUG 40 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG passwordMinLength: 2025-05-07T18:06:35Z DEBUG 8 2025-05-07T18:06:35Z DEBUG passwordMinDigits: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinAlphas: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinUppers: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinLowers: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinSpecials: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMin8bit: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinCategories: 2025-05-07T18:06:35Z DEBUG 3 2025-05-07T18:06:35Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:35Z DEBUG 3 2025-05-07T18:06:35Z DEBUG passwordPalindrome: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordDictCheck: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordDictPath: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG passwordUserAttributes: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG passwordBadWords: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG passwordMaxSequence: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:35Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:35Z DEBUG replication-only 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 500 2025-05-07T18:06:35Z DEBUG passwordMaxFailure: 2025-05-07T18:06:35Z DEBUG 3 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:35Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-security: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordMaxAge: 2025-05-07T18:06:35Z DEBUG 8640000 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG week 2025-05-07T18:06:35Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:35Z DEBUG -1 2025-05-07T18:06:35Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:35Z DEBUG -1 2025-05-07T18:06:35Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:35Z DEBUG -1 2025-05-07T18:06:35Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 2 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:35Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:35Z DEBUG passwordChange: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:35Z DEBUG 256 2025-05-07T18:06:35Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:35Z DEBUG 256 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG week 2025-05-07T18:06:35Z DEBUG nsslapd-securePort: 2025-05-07T18:06:35Z DEBUG 636 2025-05-07T18:06:35Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:35Z DEBUG 3600 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:35Z DEBUG 185 2025-05-07T18:06:35Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG passwordExp: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG day 2025-05-07T18:06:35Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:35Z DEBUG 3600 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:35Z DEBUG 3600 2025-05-07T18:06:35Z DEBUG nsslapd-nagle: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:35Z DEBUG default 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:35Z DEBUG %FT%TZ 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:35Z DEBUG default 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:35Z DEBUG %FT%TZ 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:35Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:35Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:35Z DEBUG cn=Directory Manager 2025-05-07T18:06:35Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:35Z DEBUG uidNumber 2025-05-07T18:06:35Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:35Z DEBUG gidNumber 2025-05-07T18:06:35Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:35Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:35Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:35Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG nsslapd-counters: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 2 2025-05-07T18:06:35Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:35Z DEBUG cn=Directory Manager 2025-05-07T18:06:35Z DEBUG passwordMinAge: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:35Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:35Z DEBUG 209715200 2025-05-07T18:06:35Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:35Z DEBUG 2097152 2025-05-07T18:06:35Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:35Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:35Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:35Z DEBUG 524288 2025-05-07T18:06:35Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:35Z DEBUG allowed 2025-05-07T18:06:35Z DEBUG nsslapd-config: 2025-05-07T18:06:35Z DEBUG cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:35Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:35Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:35Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:35Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:35Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:35Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:35Z DEBUG /tmp 2025-05-07T18:06:35Z DEBUG nsslapd-certdir: 2025-05-07T18:06:35Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:35Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:35Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:35Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:35Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:35Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-rundir: 2025-05-07T18:06:35Z DEBUG /run/dirsrv 2025-05-07T18:06:35Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:35Z DEBUG 300000 2025-05-07T18:06:35Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-localssf: 2025-05-07T18:06:35Z DEBUG 71 2025-05-07T18:06:35Z DEBUG nsslapd-minssf: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:35Z DEBUG next 2025-05-07T18:06:35Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:35Z DEBUG warn 2025-05-07T18:06:35Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:35Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:35Z DEBUG 2097152 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:35Z DEBUG 60 2025-05-07T18:06:35Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:35Z DEBUG 20971520 2025-05-07T18:06:35Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:35Z DEBUG nolog 2025-05-07T18:06:35Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:35Z DEBUG 2097152 2025-05-07T18:06:35Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:35Z DEBUG 128 2025-05-07T18:06:35Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:35Z DEBUG -10 2025-05-07T18:06:35Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:35Z DEBUG -10 2025-05-07T18:06:35Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:35Z DEBUG -10 2025-05-07T18:06:35Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:35Z DEBUG -1 2025-05-07T18:06:35Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 2 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG week 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 500 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 10 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:35Z DEBUG month 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:35Z DEBUG week 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:35Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:35Z DEBUG dirsrv-log 2025-05-07T18:06:35Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:35Z DEBUG none 2025-05-07T18:06:35Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:35Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:35Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:35Z DEBUG process-safe 2025-05-07T18:06:35Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:35Z DEBUG 3600 2025-05-07T18:06:35Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:35Z DEBUG 30 2025-05-07T18:06:35Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:35Z DEBUG 300 2025-05-07T18:06:35Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:35Z DEBUG 300 2025-05-07T18:06:35Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG passwordStorageScheme: 2025-05-07T18:06:35Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:35Z DEBUG passwordAdminDN: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:35Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:35Z DEBUG 2025-05-07T18:06:35Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:35Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Updated 1 2025-05-07T18:06:35Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG New entry: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG retrieve certificate 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG retrieve certificate 2025-05-07T18:06:35Z DEBUG New entry: cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG request certificate 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG request certificate 2025-05-07T18:06:35Z DEBUG New entry: cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG request certificate different host 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG request certificate different host 2025-05-07T18:06:35Z DEBUG New entry: cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG certificate status 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG certificate status 2025-05-07T18:06:35Z DEBUG New entry: cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG revoke certificate 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG revoke certificate 2025-05-07T18:06:35Z DEBUG New entry: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG certificate remove hold 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG certificate remove hold 2025-05-07T18:06:35Z DEBUG New entry: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG request certificate ignore caacl 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG request certificate ignore caacl 2025-05-07T18:06:35Z DEBUG New entry: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Request Certificate ignoring CA ACLs 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Request Certificate ignoring CA ACLs 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG domain 2025-05-07T18:06:35Z DEBUG pilotObject 2025-05-07T18:06:35Z DEBUG domainRelatedObject 2025-05-07T18:06:35Z DEBUG nisDomainObject 2025-05-07T18:06:35Z DEBUG dc: 2025-05-07T18:06:35Z DEBUG ufreeipa 2025-05-07T18:06:35Z DEBUG info: 2025-05-07T18:06:35Z DEBUG IPA V2.0 2025-05-07T18:06:35Z DEBUG associatedDomain: 2025-05-07T18:06:35Z DEBUG ufreeipa.test 2025-05-07T18:06:35Z DEBUG nisDomain: 2025-05-07T18:06:35Z DEBUG ufreeipa.test 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG add: '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG domain 2025-05-07T18:06:35Z DEBUG pilotObject 2025-05-07T18:06:35Z DEBUG domainRelatedObject 2025-05-07T18:06:35Z DEBUG nisDomainObject 2025-05-07T18:06:35Z DEBUG dc: 2025-05-07T18:06:35Z DEBUG ufreeipa 2025-05-07T18:06:35Z DEBUG info: 2025-05-07T18:06:35Z DEBUG IPA V2.0 2025-05-07T18:06:35Z DEBUG associatedDomain: 2025-05-07T18:06:35Z DEBUG ufreeipa.test 2025-05-07T18:06:35Z DEBUG nisDomain: 2025-05-07T18:06:35Z DEBUG ufreeipa.test 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG [(0, 'aci', ['(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Updated 1 2025-05-07T18:06:35Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG New entry: cn=RBAC Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG RBAC Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read roles, privileges, permissions and ACIs 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG RBAC Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read roles, privileges, permissions and ACIs 2025-05-07T18:06:35Z DEBUG New entry: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Password Policy Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read password policies 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Password Policy Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read password policies 2025-05-07T18:06:35Z DEBUG New entry: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Kerberos Ticket Policy Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read global and per-user Kerberos ticket policy 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Kerberos Ticket Policy Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read global and per-user Kerberos ticket policy 2025-05-07T18:06:35Z DEBUG New entry: cn=Automember Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Automember Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read Automember definitions 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Automember Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read Automember definitions 2025-05-07T18:06:35Z DEBUG New entry: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG IPA Masters Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read list of IPA masters 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG IPA Masters Readers 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG Read list of IPA masters 2025-05-07T18:06:35Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG masters 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=master.ufreeipa.test,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:35Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nsContainer 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG masters 2025-05-07T18:06:35Z DEBUG aci: 2025-05-07T18:06:35Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:35Z DEBUG [(0, 'aci', ['(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Updated 1 2025-05-07T18:06:35Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', b'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:35Z DEBUG Done 2025-05-07T18:06:35Z DEBUG New entry: cn=PassSync Service,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG PassSync Service 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG PassSync Service 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG nestedgroup 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG PassSync Service 2025-05-07T18:06:35Z DEBUG description: 2025-05-07T18:06:35Z DEBUG PassSync Service 2025-05-07T18:06:35Z DEBUG New entry: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Read PassSync Managers Configuration 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG ipapermissiontype: 2025-05-07T18:06:35Z DEBUG SYSTEM 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Final value after applying updates 2025-05-07T18:06:35Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG groupofnames 2025-05-07T18:06:35Z DEBUG ipapermission 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG Read PassSync Managers Configuration 2025-05-07T18:06:35Z DEBUG member: 2025-05-07T18:06:35Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:35Z DEBUG ipapermissiontype: 2025-05-07T18:06:35Z DEBUG SYSTEM 2025-05-07T18:06:35Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:35Z DEBUG --------------------------------------------- 2025-05-07T18:06:35Z DEBUG Initial value 2025-05-07T18:06:35Z DEBUG dn: cn=config 2025-05-07T18:06:35Z DEBUG cn: 2025-05-07T18:06:35Z DEBUG config 2025-05-07T18:06:35Z DEBUG objectClass: 2025-05-07T18:06:35Z DEBUG top 2025-05-07T18:06:35Z DEBUG extensibleObject 2025-05-07T18:06:35Z DEBUG nsslapdConfig 2025-05-07T18:06:35Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:35Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-betype: 2025-05-07T18:06:35Z DEBUG ldbm database 2025-05-07T18:06:35Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:35Z DEBUG cn=schema 2025-05-07T18:06:35Z DEBUG cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-plugin: 2025-05-07T18:06:35Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:35Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:35Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:35Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:35Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:35Z DEBUG 10 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:35Z DEBUG 8192 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:35Z DEBUG 600 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-port: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:35Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:35Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:35Z DEBUG 5 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG nsslapd-localuser: 2025-05-07T18:06:35Z DEBUG dirsrv 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG passwordInHistory: 2025-05-07T18:06:35Z DEBUG 6 2025-05-07T18:06:35Z DEBUG passwordUnlock: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG passwordGraceLimit: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:35Z DEBUG 1 2025-05-07T18:06:35Z DEBUG passwordMustChange: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:35Z DEBUG 100000 2025-05-07T18:06:35Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG passwordWarning: 2025-05-07T18:06:35Z DEBUG 86400 2025-05-07T18:06:35Z DEBUG nsslapd-readonly: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:35Z DEBUG on 2025-05-07T18:06:35Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:35Z DEBUG 16 2025-05-07T18:06:35Z DEBUG passwordLockout: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:35Z DEBUG off 2025-05-07T18:06:35Z DEBUG nsslapd-localhost: 2025-05-07T18:06:35Z DEBUG master.ufreeipa.test 2025-05-07T18:06:35Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:35Z DEBUG 10000 2025-05-07T18:06:35Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:35Z DEBUG 40 2025-05-07T18:06:35Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:35Z DEBUG 100 2025-05-07T18:06:35Z DEBUG passwordMinLength: 2025-05-07T18:06:35Z DEBUG 8 2025-05-07T18:06:35Z DEBUG passwordMinDigits: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinAlphas: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinUppers: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinLowers: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinSpecials: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMin8bit: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:35Z DEBUG 0 2025-05-07T18:06:35Z DEBUG passwordMinCategories: 2025-05-07T18:06:35Z DEBUG 3 2025-05-07T18:06:35Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:35Z DEBUG 3 2025-05-07T18:06:35Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Updated 1 2025-05-07T18:06:36Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG New entry: cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Read Replication Changelog Configuration 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Read Replication Changelog Configuration 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG add: '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG [(0, 'aci', ['(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Updated 1 2025-05-07T18:06:36Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG New entry: cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Write Replication Changelog Configuration 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Write Replication Changelog Configuration 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG add: '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG [(0, 'aci', ['(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Updated 1 2025-05-07T18:06:36Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG New entry: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Modify PassSync Managers Configuration 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Modify PassSync Managers Configuration 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG add: '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG [(0, 'aci', ['(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Updated 1 2025-05-07T18:06:36Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG New entry: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Read LDBM Database Configuration 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Read LDBM Database Configuration 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Updated 1 2025-05-07T18:06:36Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG New entry: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Add Configuration Sub-Entries 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG ipapermission 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Add Configuration Sub-Entries 2025-05-07T18:06:36Z DEBUG member: 2025-05-07T18:06:36Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG ipapermissiontype: 2025-05-07T18:06:36Z DEBUG SYSTEM 2025-05-07T18:06:36Z DEBUG Updating existing entry: cn=config 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG add: '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG nsslapdConfig 2025-05-07T18:06:36Z DEBUG nsslapd-backendconfig: 2025-05-07T18:06:36Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-betype: 2025-05-07T18:06:36Z DEBUG ldbm database 2025-05-07T18:06:36Z DEBUG nsslapd-privatenamespaces: 2025-05-07T18:06:36Z DEBUG cn=schema 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-plugin: 2025-05-07T18:06:36Z DEBUG cn=binary syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=country string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=fax syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=guide syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=in chain,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integer syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=oid syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=inchainmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-requiresrestart: 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-port 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-secureport 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapifilepath 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-ldapilisten 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-workingdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-sslclientauth 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogdir 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogsuffix 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxentries 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-changelogmaxage 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-db-locks 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-maxdescriptors 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-numlisteners 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-return-exact-case 2025-05-07T18:06:36Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2025-05-07T18:06:36Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nssslclientauth 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl2 2025-05-07T18:06:36Z DEBUG cn=encryption,cn=config:nsssl3 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-level: 2025-05-07T18:06:36Z DEBUG 8192 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-compress: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-compress: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-port: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-workingdir: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-maxthreadsperconn: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-localuser: 2025-05-07T18:06:36Z DEBUG dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordInHistory: 2025-05-07T18:06:36Z DEBUG 6 2025-05-07T18:06:36Z DEBUG passwordUnlock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordGraceLimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordAdminSkipInfoUpdate: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG passwordMustChange: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-local: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-pwpolicy-inherit-global: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-sizelimit: 2025-05-07T18:06:36Z DEBUG 100000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordWarning: 2025-05-07T18:06:36Z DEBUG 86400 2025-05-07T18:06:36Z DEBUG nsslapd-readonly: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-mapping-fallback: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-threadnumber: 2025-05-07T18:06:36Z DEBUG 16 2025-05-07T18:06:36Z DEBUG passwordLockout: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enquote-sup-oc: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-localhost: 2025-05-07T18:06:36Z DEBUG master.ufreeipa.test 2025-05-07T18:06:36Z DEBUG nsslapd-ioblocktimeout: 2025-05-07T18:06:36Z DEBUG 10000 2025-05-07T18:06:36Z DEBUG nsslapd-max-filter-nest-level: 2025-05-07T18:06:36Z DEBUG 40 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG passwordMinLength: 2025-05-07T18:06:36Z DEBUG 8 2025-05-07T18:06:36Z DEBUG passwordMinDigits: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinAlphas: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinUppers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinLowers: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinSpecials: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMin8bit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxRepeats: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMinCategories: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordMinTokenLength: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG passwordPalindrome: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictCheck: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordDictPath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordUserAttributes: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordBadWords: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordMaxSequence: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxSeqSets: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG passwordMaxClassChars: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/errors 2025-05-07T18:06:36Z DEBUG nsslapd-external-libs-debug-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-schemacheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-schemamod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxcheck: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-syntaxlogging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-dn-validate-strict: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ds4-compatible-schema: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-schemareplace: 2025-05-07T18:06:36Z DEBUG replication-only 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG passwordMaxFailure: 2025-05-07T18:06:36Z DEBUG 3 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/access 2025-05-07T18:06:36Z DEBUG nsslapd-lastmod: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-security: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordMaxAge: 2025-05-07T18:06:36Z DEBUG 8640000 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG passwordResetFailureCount: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG passwordTPRMaxUse: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayExpireAt: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordTPRDelayValidFrom: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG passwordIsGlobalPolicy: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordLegacyPolicy: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordTrackUpdateTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-groupevalnestlevel: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-rootpw: 2025-05-07T18:06:36Z DEBUG {PBKDF2-SHA512}100000$HPuwlZRhbvLSGvtv/aQWUtSHoxLheczY$VHDHWwI8PFrxz/bxXwqY3skxyHKucoC3swXT9HHuIMtYlHKpaJz/M2J51l8V3BT1rc+5uVw4IrPZO94Z03/RoQ== 2025-05-07T18:06:36Z DEBUG passwordChange: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-statlog-level: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-level: 2025-05-07T18:06:36Z DEBUG 256 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securePort: 2025-05-07T18:06:36Z DEBUG 636 2025-05-07T18:06:36Z DEBUG nsslapd-certmap-basedn: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-timelimit: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-reservedescriptors: 2025-05-07T18:06:36Z DEBUG 185 2025-05-07T18:06:36Z DEBUG nsslapd-svrtab: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG passwordExp: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG passwordSendExpiringTime: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-accesscontrol: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG day 2025-05-07T18:06:36Z DEBUG passwordLockoutDuration: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-idletimeout: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-nagle: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-display-attrs: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-log-format: 2025-05-07T18:06:36Z DEBUG default 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-time-format: 2025-05-07T18:06:36Z DEBUG %FT%TZ 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logbuffering: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-logbuffering: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-csnlogging: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-allow-hashed-passwords: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordCheckSyntax: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-snmp-index: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-ldapifilepath: 2025-05-07T18:06:36Z DEBUG /run/slapd-UFREEIPA-TEST.socket 2025-05-07T18:06:36Z DEBUG nsslapd-ldapilisten: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiautobind: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaprootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG nsslapd-ldapimaptoentries: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapiuidnumbertype: 2025-05-07T18:06:36Z DEBUG uidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapigidnumbertype: 2025-05-07T18:06:36Z DEBUG gidNumber 2025-05-07T18:06:36Z DEBUG nsslapd-ldapientrysearchbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-ldapidnmappingbase: 2025-05-07T18:06:36Z DEBUG cn=auto_bind,cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-anonlimitsdn: 2025-05-07T18:06:36Z DEBUG cn=anonymous-limits,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-counters: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-securelistenhost: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-rootdn: 2025-05-07T18:06:36Z DEBUG cn=Directory Manager 2025-05-07T18:06:36Z DEBUG passwordMinAge: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-return-exact-case: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-result-tweak: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-binddn-tracking: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-moddn-aci: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-targetfilter-cache: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-attribute-name-exceptions: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-maxbersize: 2025-05-07T18:06:36Z DEBUG 209715200 2025-05-07T18:06:36Z DEBUG nsslapd-maxsasliosize: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-versionstring: 2025-05-07T18:06:36Z DEBUG 389-Directory/3.1.2 2025-05-07T18:06:36Z DEBUG nsslapd-referralmode: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-numlisteners: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-maxdescriptors: 2025-05-07T18:06:36Z DEBUG 524288 2025-05-07T18:06:36Z DEBUG nsslapd-SSLclientAuth: 2025-05-07T18:06:36Z DEBUG allowed 2025-05-07T18:06:36Z DEBUG nsslapd-config: 2025-05-07T18:06:36Z DEBUG cn=config 2025-05-07T18:06:36Z DEBUG nsslapd-instancedir: 2025-05-07T18:06:36Z DEBUG /usr/lib64/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-schemadir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST/schema 2025-05-07T18:06:36Z DEBUG nsslapd-lockdir: 2025-05-07T18:06:36Z DEBUG /run/lock/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-tmpdir: 2025-05-07T18:06:36Z DEBUG /tmp 2025-05-07T18:06:36Z DEBUG nsslapd-certdir: 2025-05-07T18:06:36Z DEBUG /etc/dirsrv/slapd-UFREEIPA-TEST 2025-05-07T18:06:36Z DEBUG nsslapd-ldifdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/ldif 2025-05-07T18:06:36Z DEBUG nsslapd-bakdir: 2025-05-07T18:06:36Z DEBUG /var/lib/dirsrv/slapd-UFREEIPA-TEST/bak 2025-05-07T18:06:36Z DEBUG nsslapd-saslpath: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rundir: 2025-05-07T18:06:36Z DEBUG /run/dirsrv 2025-05-07T18:06:36Z DEBUG nsslapd-rewrite-rfc1274: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-outbound-ldap-io-timeout: 2025-05-07T18:06:36Z DEBUG 300000 2025-05-07T18:06:36Z DEBUG nsslapd-allow-unauthenticated-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-require-secure-binds: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-close-on-failed-bind: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-allow-anonymous-access: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-localssf: 2025-05-07T18:06:36Z DEBUG 71 2025-05-07T18:06:36Z DEBUG nsslapd-minssf: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-minssf-exclude-rootdse: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-force-sasl-external: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-global: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-entryusn-import-initval: 2025-05-07T18:06:36Z DEBUG next 2025-05-07T18:06:36Z DEBUG nsslapd-validate-cert: 2025-05-07T18:06:36Z DEBUG warn 2025-05-07T18:06:36Z DEBUG nsslapd-pagedsizelimit: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-defaultnamingcontext: 2025-05-07T18:06:36Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-threshold: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-grace-period: 2025-05-07T18:06:36Z DEBUG 60 2025-05-07T18:06:36Z DEBUG nsslapd-disk-monitoring-logging-critical: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ndn-cache-max-size: 2025-05-07T18:06:36Z DEBUG 20971520 2025-05-07T18:06:36Z DEBUG nsslapd-allowed-sasl-mechanisms: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-virtual-attrs: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-unhashed-pw-switch: 2025-05-07T18:06:36Z DEBUG nolog 2025-05-07T18:06:36Z DEBUG nsslapd-sasl-max-buffer-size: 2025-05-07T18:06:36Z DEBUG 2097152 2025-05-07T18:06:36Z DEBUG nsslapd-search-return-original-type-switch: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-enable-turbo-mode: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-connection-buffer: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-connection-nocanon: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-logging: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-listen-backlog-size: 2025-05-07T18:06:36Z DEBUG 128 2025-05-07T18:06:36Z DEBUG nsslapd-dynamic-plugins: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mxfast: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-trim-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-malloc-mmap-threshold: 2025-05-07T18:06:36Z DEBUG -10 2025-05-07T18:06:36Z DEBUG nsslapd-ignore-time-skew: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-global-backend-lock: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-maxsimplepaged-per-conn: 2025-05-07T18:06:36Z DEBUG -1 2025-05-07T18:06:36Z DEBUG nsslapd-enable-nunc-stans: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 2 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/audit 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-mode: 2025-05-07T18:06:36Z DEBUG 600 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsynchour: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2025-05-07T18:06:36Z DEBUG 0 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2025-05-07T18:06:36Z DEBUG 500 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsize: 2025-05-07T18:06:36Z DEBUG 100 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtime: 2025-05-07T18:06:36Z DEBUG 1 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-maxlogsperdir: 2025-05-07T18:06:36Z DEBUG 10 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logging-enabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2025-05-07T18:06:36Z DEBUG month 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logminfreediskspace: 2025-05-07T18:06:36Z DEBUG 5 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2025-05-07T18:06:36Z DEBUG week 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog: 2025-05-07T18:06:36Z DEBUG /var/log/dirsrv/slapd-UFREEIPA-TEST/security 2025-05-07T18:06:36Z DEBUG nsslapd-extract-pemfiles: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-logging-backend: 2025-05-07T18:06:36Z DEBUG dirsrv-log 2025-05-07T18:06:36Z DEBUG nsslapd-tls-check-crl: 2025-05-07T18:06:36Z DEBUG none 2025-05-07T18:06:36Z DEBUG nsslapd-enable-upgrade-hash: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-scheme-list-no-upgrade-hash: 2025-05-07T18:06:36Z DEBUG CRYPT,CLEAR 2025-05-07T18:06:36Z DEBUG nsslapd-verify-filter-schema: 2025-05-07T18:06:36Z DEBUG process-safe 2025-05-07T18:06:36Z DEBUG nsslapd-enable-ldapssotoken: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2025-05-07T18:06:36Z DEBUG 3600 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-fin-timeout: 2025-05-07T18:06:36Z DEBUG 30 2025-05-07T18:06:36Z DEBUG nsslapd-tcp-keepalive-time: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-referral-check-period: 2025-05-07T18:06:36Z DEBUG 300 2025-05-07T18:06:36Z DEBUG nsslapd-return-original-entrydn: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG passwordStorageScheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG passwordAdminDN: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-rootpwstoragescheme: 2025-05-07T18:06:36Z DEBUG PBKDF2-SHA512 2025-05-07T18:06:36Z DEBUG nsslapd-errorlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-accesslog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-auditlog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ssl-check-hostname: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-hash-filters: 2025-05-07T18:06:36Z DEBUG off 2025-05-07T18:06:36Z DEBUG nsslapd-auditfaillog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-securitylog-list: 2025-05-07T18:06:36Z DEBUG 2025-05-07T18:06:36Z DEBUG nsslapd-ldapssotoken-secret: 2025-05-07T18:06:36Z DEBUG iDkodjWs3VTt18u1gl_QJjAQdUWm5dUbh_7BYHwpjmY= 2025-05-07T18:06:36Z DEBUG aci: 2025-05-07T18:06:36Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2025-05-07T18:06:36Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:36Z DEBUG [(0, 'aci', ['(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Updated 1 2025-05-07T18:06:36Z DEBUG update_entry modlist [(0, 'aci', [b'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG New entry: cn=CA Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG CA Administrator 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG CA Administrator 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG CA Administrator 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG CA Administrator 2025-05-07T18:06:36Z DEBUG New entry: cn=Vault Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Vault Administrators 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG Vault Administrators 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG Vault Administrators 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG Vault Administrators 2025-05-07T18:06:36Z DEBUG Updating existing entry: cn=DNS Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG DNS Administrators 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG DNS Administrators 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG DNS Administrators 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG DNS Administrators 2025-05-07T18:06:36Z DEBUG [] 2025-05-07T18:06:36Z DEBUG Updated 0 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG Updating existing entry: cn=DNS Servers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG DNS Servers 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG DNS Servers 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG DNS Servers 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG DNS Servers 2025-05-07T18:06:36Z DEBUG [] 2025-05-07T18:06:36Z DEBUG Updated 0 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG Updating existing entry: cn=External IdP server Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=External IdP server Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG External IdP server Administrators 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG External IdP server Administrators 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=External IdP server Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG groupofnames 2025-05-07T18:06:36Z DEBUG nestedgroup 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG External IdP server Administrators 2025-05-07T18:06:36Z DEBUG description: 2025-05-07T18:06:36Z DEBUG External IdP server Administrators 2025-05-07T18:06:36Z DEBUG [] 2025-05-07T18:06:36Z DEBUG Updated 0 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-delegation.update 1.901 sec 2025-05-07T18:06:36Z DEBUG Parsing update file '/usr/share/ipa/updates/40-dns.update' 2025-05-07T18:06:36Z DEBUG New entry: cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG addifexist: 'idnsConfigObject' to objectClass, current value [] 2025-05-07T18:06:36Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2025-05-07T18:06:36Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2025-05-07T18:06:36Z DEBUG addifexist: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' to aci, current value [] 2025-05-07T18:06:36Z DEBUG addifexist: '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value [] 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG New entry: cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG replace: (targetattr = "*")(version 3.0; acl "No access to DNS tree without a permission"; deny (read,search,compare) (groupdn != "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test") and (groupdn != "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test");) not found, skipping 2025-05-07T18:06:36Z DEBUG replace: (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";) not found, skipping 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG New entry: cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2025-05-07T18:06:36Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2025-05-07T18:06:36Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2025-05-07T18:06:36Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2025-05-07T18:06:36Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2025-05-07T18:06:36Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2025-05-07T18:06:36Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2025-05-07T18:06:36Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG Updating existing entry: cn=IPA DNS,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG IPA DNS 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:36Z DEBUG database 2025-05-07T18:06:36Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:36Z DEBUG IPA DNS support plugin 2025-05-07T18:06:36Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:36Z DEBUG ipa_dns 2025-05-07T18:06:36Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:36Z DEBUG ipadns_init 2025-05-07T18:06:36Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:36Z DEBUG libipa_dns.so 2025-05-07T18:06:36Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:36Z DEBUG preoperation 2025-05-07T18:06:36Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:36Z DEBUG Red Hat, Inc. 2025-05-07T18:06:36Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:36Z DEBUG 1.0 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG nsslapdPlugin 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG IPA DNS 2025-05-07T18:06:36Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:36Z DEBUG database 2025-05-07T18:06:36Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:36Z DEBUG IPA DNS support plugin 2025-05-07T18:06:36Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:36Z DEBUG on 2025-05-07T18:06:36Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:36Z DEBUG ipa_dns 2025-05-07T18:06:36Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:36Z DEBUG ipadns_init 2025-05-07T18:06:36Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:36Z DEBUG libipa_dns.so 2025-05-07T18:06:36Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:36Z DEBUG preoperation 2025-05-07T18:06:36Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:36Z DEBUG Red Hat, Inc. 2025-05-07T18:06:36Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:36Z DEBUG 1.0 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG nsslapdPlugin 2025-05-07T18:06:36Z DEBUG extensibleObject 2025-05-07T18:06:36Z DEBUG [] 2025-05-07T18:06:36Z DEBUG Updated 0 2025-05-07T18:06:36Z DEBUG Done 2025-05-07T18:06:36Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-dns.update 0.025 sec 2025-05-07T18:06:36Z DEBUG Parsing update file '/usr/share/ipa/updates/40-idp.update' 2025-05-07T18:06:36Z DEBUG New entry: cn=idp,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=idp,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG nsContainer 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG idp 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=idp,dc=ufreeipa,dc=test 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG nsContainer 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG idp 2025-05-07T18:06:36Z DEBUG New entry: cn=ipaidpconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Initial value 2025-05-07T18:06:36Z DEBUG dn: cn=ipaidpconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG nsIndex 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG nsSystemIndex: 2025-05-07T18:06:36Z DEBUG false 2025-05-07T18:06:36Z DEBUG only: set cn to 'ipaidpconfiglink', current value [] 2025-05-07T18:06:36Z DEBUG only: updated value ['ipaidpconfiglink'] 2025-05-07T18:06:36Z DEBUG add: 'eq' to nsIndexType, current value [] 2025-05-07T18:06:36Z DEBUG add: updated value ['eq'] 2025-05-07T18:06:36Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2025-05-07T18:06:36Z DEBUG add: updated value ['eq', 'pres'] 2025-05-07T18:06:36Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2025-05-07T18:06:36Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2025-05-07T18:06:36Z DEBUG --------------------------------------------- 2025-05-07T18:06:36Z DEBUG Final value after applying updates 2025-05-07T18:06:36Z DEBUG dn: cn=ipaidpconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:36Z DEBUG objectClass: 2025-05-07T18:06:36Z DEBUG nsIndex 2025-05-07T18:06:36Z DEBUG top 2025-05-07T18:06:36Z DEBUG nsSystemIndex: 2025-05-07T18:06:36Z DEBUG false 2025-05-07T18:06:36Z DEBUG cn: 2025-05-07T18:06:36Z DEBUG ipaidpconfiglink 2025-05-07T18:06:36Z DEBUG nsIndexType: 2025-05-07T18:06:36Z DEBUG eq 2025-05-07T18:06:36Z DEBUG pres 2025-05-07T18:06:36Z DEBUG sub 2025-05-07T18:06:36Z DEBUG Creating task cn=indextask_139659339967896160_15571,cn=index,cn=tasks,cn=config to index attributes: ipaidpconfiglink 2025-05-07T18:06:37Z DEBUG Indexing finished 2025-05-07T18:06:37Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-idp.update 1.071 sec 2025-05-07T18:06:37Z DEBUG Parsing update file '/usr/share/ipa/updates/40-otp.update' 2025-05-07T18:06:37Z DEBUG New entry: cn=otp,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Initial value 2025-05-07T18:06:37Z DEBUG dn: cn=otp,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG nsContainer 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG otp 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Final value after applying updates 2025-05-07T18:06:37Z DEBUG dn: cn=otp,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG nsContainer 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG otp 2025-05-07T18:06:37Z DEBUG New entry: cn=otp,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Initial value 2025-05-07T18:06:37Z DEBUG dn: cn=otp,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG ipatokenOTPConfig 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG otp 2025-05-07T18:06:37Z DEBUG ipatokenTOTPauthWindow: 2025-05-07T18:06:37Z DEBUG 300 2025-05-07T18:06:37Z DEBUG ipatokenTOTPsyncWindow: 2025-05-07T18:06:37Z DEBUG 86400 2025-05-07T18:06:37Z DEBUG ipatokenHOTPauthWindow: 2025-05-07T18:06:37Z DEBUG 10 2025-05-07T18:06:37Z DEBUG ipatokenHOTPsyncWindow: 2025-05-07T18:06:37Z DEBUG 100 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Final value after applying updates 2025-05-07T18:06:37Z DEBUG dn: cn=otp,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG ipatokenOTPConfig 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG otp 2025-05-07T18:06:37Z DEBUG ipatokenTOTPauthWindow: 2025-05-07T18:06:37Z DEBUG 300 2025-05-07T18:06:37Z DEBUG ipatokenTOTPsyncWindow: 2025-05-07T18:06:37Z DEBUG 86400 2025-05-07T18:06:37Z DEBUG ipatokenHOTPauthWindow: 2025-05-07T18:06:37Z DEBUG 10 2025-05-07T18:06:37Z DEBUG ipatokenHOTPsyncWindow: 2025-05-07T18:06:37Z DEBUG 100 2025-05-07T18:06:37Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Initial value 2025-05-07T18:06:37Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG domain 2025-05-07T18:06:37Z DEBUG pilotObject 2025-05-07T18:06:37Z DEBUG domainRelatedObject 2025-05-07T18:06:37Z DEBUG nisDomainObject 2025-05-07T18:06:37Z DEBUG dc: 2025-05-07T18:06:37Z DEBUG ufreeipa 2025-05-07T18:06:37Z DEBUG info: 2025-05-07T18:06:37Z DEBUG IPA V2.0 2025-05-07T18:06:37Z DEBUG associatedDomain: 2025-05-07T18:06:37Z DEBUG ufreeipa.test 2025-05-07T18:06:37Z DEBUG nisDomain: 2025-05-07T18:06:37Z DEBUG ufreeipa.test 2025-05-07T18:06:37Z DEBUG aci: 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:37Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:37Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:37Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:37Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:37Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:37Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:37Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:37Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:37Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' not in aci 2025-05-07T18:06:37Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:37Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' not in aci 2025-05-07T18:06:37Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:37Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' not in aci 2025-05-07T18:06:37Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:37Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2025-05-07T18:06:37Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:37Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2025-05-07T18:06:37Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:37Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2025-05-07T18:06:37Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Final value after applying updates 2025-05-07T18:06:37Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG domain 2025-05-07T18:06:37Z DEBUG pilotObject 2025-05-07T18:06:37Z DEBUG domainRelatedObject 2025-05-07T18:06:37Z DEBUG nisDomainObject 2025-05-07T18:06:37Z DEBUG dc: 2025-05-07T18:06:37Z DEBUG ufreeipa 2025-05-07T18:06:37Z DEBUG info: 2025-05-07T18:06:37Z DEBUG IPA V2.0 2025-05-07T18:06:37Z DEBUG associatedDomain: 2025-05-07T18:06:37Z DEBUG ufreeipa.test 2025-05-07T18:06:37Z DEBUG nisDomain: 2025-05-07T18:06:37Z DEBUG ufreeipa.test 2025-05-07T18:06:37Z DEBUG aci: 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:37Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:37Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:37Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:37Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:37Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:37Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:37Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:37Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:37Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:37Z DEBUG [] 2025-05-07T18:06:37Z DEBUG Updated 0 2025-05-07T18:06:37Z DEBUG Done 2025-05-07T18:06:37Z DEBUG New entry: cn=radiusproxy,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Initial value 2025-05-07T18:06:37Z DEBUG dn: cn=radiusproxy,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG nsContainer 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG radiusproxy 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Final value after applying updates 2025-05-07T18:06:37Z DEBUG dn: cn=radiusproxy,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG nsContainer 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG radiusproxy 2025-05-07T18:06:37Z DEBUG New entry: cn=IPA OTP Last Token,cn=plugins,cn=config 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Initial value 2025-05-07T18:06:37Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2025-05-07T18:06:37Z DEBUG objectclass: 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG nsSlapdPlugin 2025-05-07T18:06:37Z DEBUG extensibleObject 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG IPA OTP Last Token 2025-05-07T18:06:37Z DEBUG nsslapd-pluginpath: 2025-05-07T18:06:37Z DEBUG libipa_otp_lasttoken 2025-05-07T18:06:37Z DEBUG nsslapd-plugininitfunc: 2025-05-07T18:06:37Z DEBUG ipa_otp_lasttoken_init 2025-05-07T18:06:37Z DEBUG nsslapd-plugintype: 2025-05-07T18:06:37Z DEBUG preoperation 2025-05-07T18:06:37Z DEBUG nsslapd-pluginenabled: 2025-05-07T18:06:37Z DEBUG on 2025-05-07T18:06:37Z DEBUG nsslapd-pluginid: 2025-05-07T18:06:37Z DEBUG ipa-otp-lasttoken 2025-05-07T18:06:37Z DEBUG nsslapd-pluginversion: 2025-05-07T18:06:37Z DEBUG 1.0 2025-05-07T18:06:37Z DEBUG nsslapd-pluginvendor: 2025-05-07T18:06:37Z DEBUG Red Hat, Inc. 2025-05-07T18:06:37Z DEBUG nsslapd-plugindescription: 2025-05-07T18:06:37Z DEBUG IPA OTP Last Token plugin 2025-05-07T18:06:37Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:37Z DEBUG database 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Final value after applying updates 2025-05-07T18:06:37Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2025-05-07T18:06:37Z DEBUG objectclass: 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG nsSlapdPlugin 2025-05-07T18:06:37Z DEBUG extensibleObject 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG IPA OTP Last Token 2025-05-07T18:06:37Z DEBUG nsslapd-pluginpath: 2025-05-07T18:06:37Z DEBUG libipa_otp_lasttoken 2025-05-07T18:06:37Z DEBUG nsslapd-plugininitfunc: 2025-05-07T18:06:37Z DEBUG ipa_otp_lasttoken_init 2025-05-07T18:06:37Z DEBUG nsslapd-plugintype: 2025-05-07T18:06:37Z DEBUG preoperation 2025-05-07T18:06:37Z DEBUG nsslapd-pluginenabled: 2025-05-07T18:06:37Z DEBUG on 2025-05-07T18:06:37Z DEBUG nsslapd-pluginid: 2025-05-07T18:06:37Z DEBUG ipa-otp-lasttoken 2025-05-07T18:06:37Z DEBUG nsslapd-pluginversion: 2025-05-07T18:06:37Z DEBUG 1.0 2025-05-07T18:06:37Z DEBUG nsslapd-pluginvendor: 2025-05-07T18:06:37Z DEBUG Red Hat, Inc. 2025-05-07T18:06:37Z DEBUG nsslapd-plugindescription: 2025-05-07T18:06:37Z DEBUG IPA OTP Last Token plugin 2025-05-07T18:06:37Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:37Z DEBUG database 2025-05-07T18:06:37Z DEBUG New entry: cn=IPA OTP Counter,cn=plugins,cn=config 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Initial value 2025-05-07T18:06:37Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2025-05-07T18:06:37Z DEBUG objectclass: 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG nsSlapdPlugin 2025-05-07T18:06:37Z DEBUG extensibleObject 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG IPA OTP Counter 2025-05-07T18:06:37Z DEBUG nsslapd-pluginpath: 2025-05-07T18:06:37Z DEBUG libipa_otp_counter 2025-05-07T18:06:37Z DEBUG nsslapd-plugininitfunc: 2025-05-07T18:06:37Z DEBUG ipa_otp_counter_init 2025-05-07T18:06:37Z DEBUG nsslapd-plugintype: 2025-05-07T18:06:37Z DEBUG preoperation 2025-05-07T18:06:37Z DEBUG nsslapd-pluginenabled: 2025-05-07T18:06:37Z DEBUG on 2025-05-07T18:06:37Z DEBUG nsslapd-pluginid: 2025-05-07T18:06:37Z DEBUG ipa-otp-counter 2025-05-07T18:06:37Z DEBUG nsslapd-pluginversion: 2025-05-07T18:06:37Z DEBUG 1.0 2025-05-07T18:06:37Z DEBUG nsslapd-pluginvendor: 2025-05-07T18:06:37Z DEBUG Red Hat, Inc. 2025-05-07T18:06:37Z DEBUG nsslapd-plugindescription: 2025-05-07T18:06:37Z DEBUG IPA OTP Counter plugin 2025-05-07T18:06:37Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:37Z DEBUG database 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Final value after applying updates 2025-05-07T18:06:37Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2025-05-07T18:06:37Z DEBUG objectclass: 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG nsSlapdPlugin 2025-05-07T18:06:37Z DEBUG extensibleObject 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG IPA OTP Counter 2025-05-07T18:06:37Z DEBUG nsslapd-pluginpath: 2025-05-07T18:06:37Z DEBUG libipa_otp_counter 2025-05-07T18:06:37Z DEBUG nsslapd-plugininitfunc: 2025-05-07T18:06:37Z DEBUG ipa_otp_counter_init 2025-05-07T18:06:37Z DEBUG nsslapd-plugintype: 2025-05-07T18:06:37Z DEBUG preoperation 2025-05-07T18:06:37Z DEBUG nsslapd-pluginenabled: 2025-05-07T18:06:37Z DEBUG on 2025-05-07T18:06:37Z DEBUG nsslapd-pluginid: 2025-05-07T18:06:37Z DEBUG ipa-otp-counter 2025-05-07T18:06:37Z DEBUG nsslapd-pluginversion: 2025-05-07T18:06:37Z DEBUG 1.0 2025-05-07T18:06:37Z DEBUG nsslapd-pluginvendor: 2025-05-07T18:06:37Z DEBUG Red Hat, Inc. 2025-05-07T18:06:37Z DEBUG nsslapd-plugindescription: 2025-05-07T18:06:37Z DEBUG IPA OTP Counter plugin 2025-05-07T18:06:37Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:37Z DEBUG database 2025-05-07T18:06:37Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-otp.update 0.124 sec 2025-05-07T18:06:37Z DEBUG Parsing update file '/usr/share/ipa/updates/40-realm_domains.update' 2025-05-07T18:06:37Z DEBUG New entry: cn=Realm Domains,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Initial value 2025-05-07T18:06:37Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG domainRelatedObject 2025-05-07T18:06:37Z DEBUG nsContainer 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG Realm Domains 2025-05-07T18:06:37Z DEBUG associatedDomain: 2025-05-07T18:06:37Z DEBUG ufreeipa.test 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Final value after applying updates 2025-05-07T18:06:37Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG domainRelatedObject 2025-05-07T18:06:37Z DEBUG nsContainer 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG Realm Domains 2025-05-07T18:06:37Z DEBUG associatedDomain: 2025-05-07T18:06:37Z DEBUG ufreeipa.test 2025-05-07T18:06:37Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-realm_domains.update 0.040 sec 2025-05-07T18:06:37Z DEBUG Parsing update file '/usr/share/ipa/updates/40-replication.update' 2025-05-07T18:06:37Z DEBUG Updating existing entry: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Initial value 2025-05-07T18:06:37Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG userRoot 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG extensibleObject 2025-05-07T18:06:37Z DEBUG nsBackendInstance 2025-05-07T18:06:37Z DEBUG nsslapd-suffix: 2025-05-07T18:06:37Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG nsslapd-cachesize: 2025-05-07T18:06:37Z DEBUG -1 2025-05-07T18:06:37Z DEBUG nsslapd-cachememsize: 2025-05-07T18:06:37Z DEBUG 512000 2025-05-07T18:06:37Z DEBUG nsslapd-readonly: 2025-05-07T18:06:37Z DEBUG off 2025-05-07T18:06:37Z DEBUG nsslapd-require-index: 2025-05-07T18:06:37Z DEBUG off 2025-05-07T18:06:37Z DEBUG nsslapd-require-internalop-index: 2025-05-07T18:06:37Z DEBUG off 2025-05-07T18:06:37Z DEBUG nsslapd-dncachememsize: 2025-05-07T18:06:37Z DEBUG 16777216 2025-05-07T18:06:37Z DEBUG aci: 2025-05-07T18:06:37Z DEBUG (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG remove: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:37Z DEBUG remove: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:37Z DEBUG add: '(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:37Z DEBUG add: updated value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:37Z DEBUG --------------------------------------------- 2025-05-07T18:06:37Z DEBUG Final value after applying updates 2025-05-07T18:06:37Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2025-05-07T18:06:37Z DEBUG cn: 2025-05-07T18:06:37Z DEBUG userRoot 2025-05-07T18:06:37Z DEBUG objectClass: 2025-05-07T18:06:37Z DEBUG top 2025-05-07T18:06:37Z DEBUG extensibleObject 2025-05-07T18:06:37Z DEBUG nsBackendInstance 2025-05-07T18:06:37Z DEBUG nsslapd-suffix: 2025-05-07T18:06:37Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:37Z DEBUG nsslapd-cachesize: 2025-05-07T18:06:37Z DEBUG -1 2025-05-07T18:06:37Z DEBUG nsslapd-cachememsize: 2025-05-07T18:06:37Z DEBUG 512000 2025-05-07T18:06:37Z DEBUG nsslapd-readonly: 2025-05-07T18:06:37Z DEBUG off 2025-05-07T18:06:37Z DEBUG nsslapd-require-index: 2025-05-07T18:06:37Z DEBUG off 2025-05-07T18:06:37Z DEBUG nsslapd-require-internalop-index: 2025-05-07T18:06:37Z DEBUG off 2025-05-07T18:06:37Z DEBUG nsslapd-dncachememsize: 2025-05-07T18:06:37Z DEBUG 16777216 2025-05-07T18:06:37Z DEBUG aci: 2025-05-07T18:06:37Z DEBUG (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:37Z DEBUG [] 2025-05-07T18:06:37Z DEBUG Updated 0 2025-05-07T18:06:37Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG ipapermission 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Modify DNA Range 2025-05-07T18:06:38Z DEBUG ipaPermissionType: 2025-05-07T18:06:38Z DEBUG SYSTEM 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG ipapermission 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Modify DNA Range 2025-05-07T18:06:38Z DEBUG ipaPermissionType: 2025-05-07T18:06:38Z DEBUG SYSTEM 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [] 2025-05-07T18:06:38Z DEBUG Updated 0 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Posix IDs 2025-05-07T18:06:38Z DEBUG dnaExcludeScope: 2025-05-07T18:06:38Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaFilter: 2025-05-07T18:06:38Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2025-05-07T18:06:38Z DEBUG dnaMagicRegen: 2025-05-07T18:06:38Z DEBUG -1 2025-05-07T18:06:38Z DEBUG dnaMaxValue: 2025-05-07T18:06:38Z DEBUG 63999999 2025-05-07T18:06:38Z DEBUG dnaNextValue: 2025-05-07T18:06:38Z DEBUG 63800000 2025-05-07T18:06:38Z DEBUG dnaScope: 2025-05-07T18:06:38Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaSharedCfgDN: 2025-05-07T18:06:38Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaThreshold: 2025-05-07T18:06:38Z DEBUG 500 2025-05-07T18:06:38Z DEBUG dnaType: 2025-05-07T18:06:38Z DEBUG uidNumber 2025-05-07T18:06:38Z DEBUG gidNumber 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG extensibleObject 2025-05-07T18:06:38Z DEBUG aci: 2025-05-07T18:06:38Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG remove: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:38Z DEBUG remove: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:38Z DEBUG add: '(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:38Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Posix IDs 2025-05-07T18:06:38Z DEBUG dnaExcludeScope: 2025-05-07T18:06:38Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaFilter: 2025-05-07T18:06:38Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2025-05-07T18:06:38Z DEBUG dnaMagicRegen: 2025-05-07T18:06:38Z DEBUG -1 2025-05-07T18:06:38Z DEBUG dnaMaxValue: 2025-05-07T18:06:38Z DEBUG 63999999 2025-05-07T18:06:38Z DEBUG dnaNextValue: 2025-05-07T18:06:38Z DEBUG 63800000 2025-05-07T18:06:38Z DEBUG dnaScope: 2025-05-07T18:06:38Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaSharedCfgDN: 2025-05-07T18:06:38Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaThreshold: 2025-05-07T18:06:38Z DEBUG 500 2025-05-07T18:06:38Z DEBUG dnaType: 2025-05-07T18:06:38Z DEBUG uidNumber 2025-05-07T18:06:38Z DEBUG gidNumber 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG extensibleObject 2025-05-07T18:06:38Z DEBUG aci: 2025-05-07T18:06:38Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG [] 2025-05-07T18:06:38Z DEBUG Updated 0 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG New entry: cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG ipapermission 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Read DNA Range 2025-05-07T18:06:38Z DEBUG ipapermissiontype: 2025-05-07T18:06:38Z DEBUG SYSTEM 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG ipapermission 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Read DNA Range 2025-05-07T18:06:38Z DEBUG ipapermissiontype: 2025-05-07T18:06:38Z DEBUG SYSTEM 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Posix IDs 2025-05-07T18:06:38Z DEBUG dnaExcludeScope: 2025-05-07T18:06:38Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaFilter: 2025-05-07T18:06:38Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2025-05-07T18:06:38Z DEBUG dnaMagicRegen: 2025-05-07T18:06:38Z DEBUG -1 2025-05-07T18:06:38Z DEBUG dnaMaxValue: 2025-05-07T18:06:38Z DEBUG 63999999 2025-05-07T18:06:38Z DEBUG dnaNextValue: 2025-05-07T18:06:38Z DEBUG 63800000 2025-05-07T18:06:38Z DEBUG dnaScope: 2025-05-07T18:06:38Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaSharedCfgDN: 2025-05-07T18:06:38Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaThreshold: 2025-05-07T18:06:38Z DEBUG 500 2025-05-07T18:06:38Z DEBUG dnaType: 2025-05-07T18:06:38Z DEBUG uidNumber 2025-05-07T18:06:38Z DEBUG gidNumber 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG extensibleObject 2025-05-07T18:06:38Z DEBUG aci: 2025-05-07T18:06:38Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG remove: '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:38Z DEBUG remove: '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:38Z DEBUG add: '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:38Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Posix IDs 2025-05-07T18:06:38Z DEBUG dnaExcludeScope: 2025-05-07T18:06:38Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaFilter: 2025-05-07T18:06:38Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2025-05-07T18:06:38Z DEBUG dnaMagicRegen: 2025-05-07T18:06:38Z DEBUG -1 2025-05-07T18:06:38Z DEBUG dnaMaxValue: 2025-05-07T18:06:38Z DEBUG 63999999 2025-05-07T18:06:38Z DEBUG dnaNextValue: 2025-05-07T18:06:38Z DEBUG 63800000 2025-05-07T18:06:38Z DEBUG dnaScope: 2025-05-07T18:06:38Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaSharedCfgDN: 2025-05-07T18:06:38Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG dnaThreshold: 2025-05-07T18:06:38Z DEBUG 500 2025-05-07T18:06:38Z DEBUG dnaType: 2025-05-07T18:06:38Z DEBUG uidNumber 2025-05-07T18:06:38Z DEBUG gidNumber 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG extensibleObject 2025-05-07T18:06:38Z DEBUG aci: 2025-05-07T18:06:38Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG (targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG [(0, 'aci', ['(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG New entry: cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG ipapermission 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Read domain level 2025-05-07T18:06:38Z DEBUG ipapermissiontype: 2025-05-07T18:06:38Z DEBUG SYSTEM 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG ipapermission 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Read domain level 2025-05-07T18:06:38Z DEBUG ipapermissiontype: 2025-05-07T18:06:38Z DEBUG SYSTEM 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nsContainer 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG masters 2025-05-07T18:06:38Z DEBUG aci: 2025-05-07T18:06:38Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:38Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:38Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG add: '(targetattr = "ipamaxdomainlevel || ipamindomainlevel")(version 3.0;acl "permission:Read domain level";allow (read, search, compare) groupdn = "ldap:///cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:38Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipamaxdomainlevel || ipamindomainlevel")(version 3.0;acl "permission:Read domain level";allow (read, search, compare) groupdn = "ldap:///cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nsContainer 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG masters 2025-05-07T18:06:38Z DEBUG aci: 2025-05-07T18:06:38Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:38Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:38Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG (targetattr = "ipamaxdomainlevel || ipamindomainlevel")(version 3.0;acl "permission:Read domain level";allow (read, search, compare) groupdn = "ldap:///cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:38Z DEBUG [(0, 'aci', ['(targetattr = "ipamaxdomainlevel || ipamindomainlevel")(version 3.0;acl "permission:Read domain level";allow (read, search, compare) groupdn = "ldap:///cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipamaxdomainlevel || ipamindomainlevel")(version 3.0;acl "permission:Read domain level";allow (read, search, compare) groupdn = "ldap:///cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-replication.update 0.172 sec 2025-05-07T18:06:38Z DEBUG Parsing update file '/usr/share/ipa/updates/40-vault.update' 2025-05-07T18:06:38Z DEBUG New entry: cn=vaults,cn=kra,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=vaults,cn=kra,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=ufreeipa,dc=test")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value [] 2025-05-07T18:06:38Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=ufreeipa,dc=test")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:38Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ufreeipa,dc=test")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)' from aci, current value [] 2025-05-07T18:06:38Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ufreeipa,dc=test")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' from aci, current value [] 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' not in aci 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' from aci, current value [] 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' not in aci 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' from aci, current value [] 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' not in aci 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' from aci, current value [] 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' not in aci 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' from aci, current value [] 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' not in aci 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' from aci, current value [] 2025-05-07T18:06:38Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' not in aci 2025-05-07T18:06:38Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ufreeipa,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test" and userattr="owner#SELFDN";)' from aci, current value [] 2025-05-07T18:06:38Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ufreeipa,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test" and userattr="owner#SELFDN";)' not in aci 2025-05-07T18:06:38Z DEBUG addifexist: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=ufreeipa,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=ufreeipa,dc=test" and userattr="owner#SELFDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ufreeipa,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=ufreeipa,dc=test" and userattr="owner#SELFDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=vaults,cn=kra,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-vault.update 0.055 sec 2025-05-07T18:06:38Z DEBUG Parsing update file '/usr/share/ipa/updates/41-caacl.update' 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=caacls,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=caacls,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nsContainer 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG caacls 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=caacls,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nsContainer 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG caacls 2025-05-07T18:06:38Z DEBUG [] 2025-05-07T18:06:38Z DEBUG Updated 0 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG LDAP update duration: /usr/share/ipa/updates/41-caacl.update 0.053 sec 2025-05-07T18:06:38Z DEBUG Parsing update file '/usr/share/ipa/updates/41-lightweight-cas.update' 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=cas,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=cas,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nsContainer 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG cas 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=cas,cn=ca,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nsContainer 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG cas 2025-05-07T18:06:38Z DEBUG [] 2025-05-07T18:06:38Z DEBUG Updated 0 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG LDAP update duration: /usr/share/ipa/updates/41-lightweight-cas.update 0.042 sec 2025-05-07T18:06:38Z DEBUG Parsing update file '/usr/share/ipa/updates/45-roles.update' 2025-05-07T18:06:38Z DEBUG New entry: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Modify Users and Reset passwords 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Modify Users and Reset passwords 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Modify Users and Reset passwords 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Modify Users and Reset passwords 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG New entry: cn=Modify Group membership,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Modify Group membership 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Modify Group membership 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Modify Group membership 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Modify Group membership 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG New entry: cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG User Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Responsible for creating Users and Groups 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG User Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Responsible for creating Users and Groups 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=User Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG User Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG User Administrators 2025-05-07T18:06:38Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG User Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG User Administrators 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Group Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Group Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Group Administrators 2025-05-07T18:06:38Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Group Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Group Administrators 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Stage User Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Stage User Administrators 2025-05-07T18:06:38Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Stage User Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Stage User Administrators 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG New entry: cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG IT Specialist 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG IT Specialist 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG IT Specialist 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG IT Specialist 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Host Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Host Administrators 2025-05-07T18:06:38Z DEBUG memberOf: 2025-05-07T18:06:38Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Host Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Host Administrators 2025-05-07T18:06:38Z DEBUG memberOf: 2025-05-07T18:06:38Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Host Group Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Host Group Administrators 2025-05-07T18:06:38Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Host Group Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Host Group Administrators 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Service Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Service Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Service Administrators 2025-05-07T18:06:38Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Service Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Service Administrators 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Automount Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Automount Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Automount Administrators 2025-05-07T18:06:38Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Automount Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Automount Administrators 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG New entry: cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG IT Security Specialist 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG IT Security Specialist 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG IT Security Specialist 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG IT Security Specialist 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Netgroups Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Netgroups Administrators 2025-05-07T18:06:38Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Netgroups Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Netgroups Administrators 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG HBAC Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG HBAC Administrator 2025-05-07T18:06:38Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG HBAC Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG HBAC Administrator 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Sudo Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Sudo Administrator 2025-05-07T18:06:38Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Sudo Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Sudo Administrator 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Security Specialist,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG New entry: cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Security Architect 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Security Architect 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Security Architect 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Security Architect 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Delegation Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Role administration 2025-05-07T18:06:38Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Delegation Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Role administration 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Replication Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Replication Administrators 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG memberOf: 2025-05-07T18:06:38Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG add: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test', 'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Replication Administrators 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Replication Administrators 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG memberOf: 2025-05-07T18:06:38Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(0, 'member', ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test', 'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(0, 'member', [b'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ufreeipa,dc=test', b'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Write IPA Configuration 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Write IPA Configuration 2025-05-07T18:06:38Z DEBUG memberOf: 2025-05-07T18:06:38Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Write IPA Configuration 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Write IPA Configuration 2025-05-07T18:06:38Z DEBUG memberOf: 2025-05-07T18:06:38Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Password Policy Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Password Policy Administrator 2025-05-07T18:06:38Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value [] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Password Policy Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Password Policy Administrator 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(2, 'member', ['cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(2, 'member', [b'cn=Security Architect,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG New entry: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Enrollment Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Enrollment Administrator 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Host Enrollment 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Host Enrollment 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG add: 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test', 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG Host Enrollment 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Host Enrollment 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [(0, 'member', ['cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Updated 1 2025-05-07T18:06:38Z DEBUG update_entry modlist [(0, 'member', [b'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test'])] 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG LDAP update duration: /usr/share/ipa/updates/45-roles.update 0.588 sec 2025-05-07T18:06:38Z DEBUG Parsing update file '/usr/share/ipa/updates/49-autobind-services.update' 2025-05-07T18:06:38Z DEBUG New entry: cn=named,cn=auto_bind,cn=config 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=named,cn=auto_bind,cn=config 2025-05-07T18:06:38Z DEBUG onlyifexist: '25' to uidNumber, current value [] 2025-05-07T18:06:38Z DEBUG onlyifexist: '25' to gidNumber, current value [] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=named,cn=auto_bind,cn=config 2025-05-07T18:06:38Z DEBUG LDAP update duration: /usr/share/ipa/updates/49-autobind-services.update 0.007 sec 2025-05-07T18:06:38Z DEBUG Parsing update file '/usr/share/ipa/updates/50-7_bit_check.update' 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG 7-bit check 2025-05-07T18:06:38Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:38Z DEBUG database 2025-05-07T18:06:38Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:38Z DEBUG Enforce 7-bit clean attribute values 2025-05-07T18:06:38Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:38Z DEBUG on 2025-05-07T18:06:38Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:38Z DEBUG NS7bitAttr 2025-05-07T18:06:38Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:38Z DEBUG NS7bitAttr_Init 2025-05-07T18:06:38Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:38Z DEBUG libattr-unique-plugin 2025-05-07T18:06:38Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:38Z DEBUG betxnpreoperation 2025-05-07T18:06:38Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:38Z DEBUG 389 Project 2025-05-07T18:06:38Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:38Z DEBUG 3.1.2 2025-05-07T18:06:38Z DEBUG nsslapd-pluginarg0: 2025-05-07T18:06:38Z DEBUG uid 2025-05-07T18:06:38Z DEBUG nsslapd-pluginarg1: 2025-05-07T18:06:38Z DEBUG mail 2025-05-07T18:06:38Z DEBUG nsslapd-pluginarg2: 2025-05-07T18:06:38Z DEBUG , 2025-05-07T18:06:38Z DEBUG nsslapd-pluginarg3: 2025-05-07T18:06:38Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG nsSlapdPlugin 2025-05-07T18:06:38Z DEBUG extensibleObject 2025-05-07T18:06:38Z DEBUG replace: userpassword not found, skipping 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG 7-bit check 2025-05-07T18:06:38Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:38Z DEBUG database 2025-05-07T18:06:38Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:38Z DEBUG Enforce 7-bit clean attribute values 2025-05-07T18:06:38Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:38Z DEBUG on 2025-05-07T18:06:38Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:38Z DEBUG NS7bitAttr 2025-05-07T18:06:38Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:38Z DEBUG NS7bitAttr_Init 2025-05-07T18:06:38Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:38Z DEBUG libattr-unique-plugin 2025-05-07T18:06:38Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:38Z DEBUG betxnpreoperation 2025-05-07T18:06:38Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:38Z DEBUG 389 Project 2025-05-07T18:06:38Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:38Z DEBUG 3.1.2 2025-05-07T18:06:38Z DEBUG nsslapd-pluginarg0: 2025-05-07T18:06:38Z DEBUG uid 2025-05-07T18:06:38Z DEBUG nsslapd-pluginarg1: 2025-05-07T18:06:38Z DEBUG mail 2025-05-07T18:06:38Z DEBUG nsslapd-pluginarg2: 2025-05-07T18:06:38Z DEBUG , 2025-05-07T18:06:38Z DEBUG nsslapd-pluginarg3: 2025-05-07T18:06:38Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG nsSlapdPlugin 2025-05-07T18:06:38Z DEBUG extensibleObject 2025-05-07T18:06:38Z DEBUG [] 2025-05-07T18:06:38Z DEBUG Updated 0 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-7_bit_check.update 0.008 sec 2025-05-07T18:06:38Z DEBUG Parsing update file '/usr/share/ipa/updates/50-dogtag10-migration.update' 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=aclResources,o=ipaca 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=aclResources,o=ipaca 2025-05-07T18:06:38Z DEBUG resourceACLS: 2025-05-07T18:06:38Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2025-05-07T18:06:38Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2025-05-07T18:06:38Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2025-05-07T18:06:38Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2025-05-07T18:06:38Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2025-05-07T18:06:38Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2025-05-07T18:06:38Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2025-05-07T18:06:38Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2025-05-07T18:06:38Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2025-05-07T18:06:38Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2025-05-07T18:06:38Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2025-05-07T18:06:38Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2025-05-07T18:06:38Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2025-05-07T18:06:38Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2025-05-07T18:06:38Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2025-05-07T18:06:38Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2025-05-07T18:06:38Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2025-05-07T18:06:38Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2025-05-07T18:06:38Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2025-05-07T18:06:38Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2025-05-07T18:06:38Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2025-05-07T18:06:38Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2025-05-07T18:06:38Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2025-05-07T18:06:38Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2025-05-07T18:06:38Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2025-05-07T18:06:38Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2025-05-07T18:06:38Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2025-05-07T18:06:38Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2025-05-07T18:06:38Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2025-05-07T18:06:38Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2025-05-07T18:06:38Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2025-05-07T18:06:38Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2025-05-07T18:06:38Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2025-05-07T18:06:38Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2025-05-07T18:06:38Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2025-05-07T18:06:38Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2025-05-07T18:06:38Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2025-05-07T18:06:38Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2025-05-07T18:06:38Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2025-05-07T18:06:38Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2025-05-07T18:06:38Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2025-05-07T18:06:38Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2025-05-07T18:06:38Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2025-05-07T18:06:38Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2025-05-07T18:06:38Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2025-05-07T18:06:38Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2025-05-07T18:06:38Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2025-05-07T18:06:38Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2025-05-07T18:06:38Z DEBUG certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG CertACLS 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG aclResources 2025-05-07T18:06:38Z DEBUG addifexist: 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations'] 2025-05-07T18:06:38Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2025-05-07T18:06:38Z DEBUG addifexist: 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2025-05-07T18:06:38Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2025-05-07T18:06:38Z DEBUG addifexist: 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2025-05-07T18:06:38Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2025-05-07T18:06:38Z DEBUG addifexist: 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2025-05-07T18:06:38Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2025-05-07T18:06:38Z DEBUG addifexist: 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2025-05-07T18:06:38Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2025-05-07T18:06:38Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group":Anybody is allowed to read domain.xml but only Subsystem group is allowed to modify the domain.xml not found, skipping 2025-05-07T18:06:38Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml not found, skipping 2025-05-07T18:06:38Z DEBUG replace: certServer.ca.connectorInfo:read,modify:allow (modify,read) group="Enterprise KRA Administrators":Only Enterprise Administrators are allowed to update the connector information not found, skipping 2025-05-07T18:06:38Z DEBUG addifexist: 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2025-05-07T18:06:38Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=aclResources,o=ipaca 2025-05-07T18:06:38Z DEBUG resourceACLS: 2025-05-07T18:06:38Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2025-05-07T18:06:38Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2025-05-07T18:06:38Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2025-05-07T18:06:38Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2025-05-07T18:06:38Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2025-05-07T18:06:38Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2025-05-07T18:06:38Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2025-05-07T18:06:38Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2025-05-07T18:06:38Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2025-05-07T18:06:38Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2025-05-07T18:06:38Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2025-05-07T18:06:38Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2025-05-07T18:06:38Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2025-05-07T18:06:38Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2025-05-07T18:06:38Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2025-05-07T18:06:38Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2025-05-07T18:06:38Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2025-05-07T18:06:38Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2025-05-07T18:06:38Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2025-05-07T18:06:38Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2025-05-07T18:06:38Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2025-05-07T18:06:38Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2025-05-07T18:06:38Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2025-05-07T18:06:38Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2025-05-07T18:06:38Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2025-05-07T18:06:38Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2025-05-07T18:06:38Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2025-05-07T18:06:38Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2025-05-07T18:06:38Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2025-05-07T18:06:38Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2025-05-07T18:06:38Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2025-05-07T18:06:38Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2025-05-07T18:06:38Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2025-05-07T18:06:38Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2025-05-07T18:06:38Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2025-05-07T18:06:38Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2025-05-07T18:06:38Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2025-05-07T18:06:38Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2025-05-07T18:06:38Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2025-05-07T18:06:38Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2025-05-07T18:06:38Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2025-05-07T18:06:38Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2025-05-07T18:06:38Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2025-05-07T18:06:38Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2025-05-07T18:06:38Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2025-05-07T18:06:38Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2025-05-07T18:06:38Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2025-05-07T18:06:38Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2025-05-07T18:06:38Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2025-05-07T18:06:38Z DEBUG certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations 2025-05-07T18:06:38Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2025-05-07T18:06:38Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2025-05-07T18:06:38Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2025-05-07T18:06:38Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2025-05-07T18:06:38Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2025-05-07T18:06:38Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG CertACLS 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG aclResources 2025-05-07T18:06:38Z DEBUG [] 2025-05-07T18:06:38Z DEBUG Updated 0 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-dogtag10-migration.update 0.010 sec 2025-05-07T18:06:38Z DEBUG Parsing update file '/usr/share/ipa/updates/50-groupuuid.update' 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG posixgroup 2025-05-07T18:06:38Z DEBUG ipausergroup 2025-05-07T18:06:38Z DEBUG ipaobject 2025-05-07T18:06:38Z DEBUG nestedGroup 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG admins 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Account administrators group 2025-05-07T18:06:38Z DEBUG gidNumber: 2025-05-07T18:06:38Z DEBUG 63800000 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG ipaUniqueID: 2025-05-07T18:06:38Z DEBUG 6b6a9b68-2b6d-11f0-bc47-fa163e36f7a6 2025-05-07T18:06:38Z DEBUG memberOf: 2025-05-07T18:06:38Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'ipaobject', 'nestedGroup'] 2025-05-07T18:06:38Z DEBUG add: updated value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'nestedGroup', 'ipaobject'] 2025-05-07T18:06:38Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['6b6a9b68-2b6d-11f0-bc47-fa163e36f7a6'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG posixgroup 2025-05-07T18:06:38Z DEBUG ipausergroup 2025-05-07T18:06:38Z DEBUG nestedGroup 2025-05-07T18:06:38Z DEBUG ipaobject 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG admins 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Account administrators group 2025-05-07T18:06:38Z DEBUG gidNumber: 2025-05-07T18:06:38Z DEBUG 63800000 2025-05-07T18:06:38Z DEBUG member: 2025-05-07T18:06:38Z DEBUG uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG ipaUniqueID: 2025-05-07T18:06:38Z DEBUG 6b6a9b68-2b6d-11f0-bc47-fa163e36f7a6 2025-05-07T18:06:38Z DEBUG memberOf: 2025-05-07T18:06:38Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Read domain level,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG [] 2025-05-07T18:06:38Z DEBUG Updated 0 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:38Z DEBUG Updating existing entry: cn=ipausers,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Initial value 2025-05-07T18:06:38Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG ipausergroup 2025-05-07T18:06:38Z DEBUG ipaobject 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Default group for all users 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG ipausers 2025-05-07T18:06:38Z DEBUG ipaUniqueID: 2025-05-07T18:06:38Z DEBUG 6b6d09e8-2b6d-11f0-a582-fa163e36f7a6 2025-05-07T18:06:38Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'nestedgroup', 'ipausergroup', 'ipaobject'] 2025-05-07T18:06:38Z DEBUG add: updated value ['top', 'groupofnames', 'nestedgroup', 'ipausergroup', 'ipaobject'] 2025-05-07T18:06:38Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['6b6d09e8-2b6d-11f0-a582-fa163e36f7a6'] 2025-05-07T18:06:38Z DEBUG --------------------------------------------- 2025-05-07T18:06:38Z DEBUG Final value after applying updates 2025-05-07T18:06:38Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:38Z DEBUG objectClass: 2025-05-07T18:06:38Z DEBUG top 2025-05-07T18:06:38Z DEBUG groupofnames 2025-05-07T18:06:38Z DEBUG nestedgroup 2025-05-07T18:06:38Z DEBUG ipausergroup 2025-05-07T18:06:38Z DEBUG ipaobject 2025-05-07T18:06:38Z DEBUG description: 2025-05-07T18:06:38Z DEBUG Default group for all users 2025-05-07T18:06:38Z DEBUG cn: 2025-05-07T18:06:38Z DEBUG ipausers 2025-05-07T18:06:38Z DEBUG ipaUniqueID: 2025-05-07T18:06:38Z DEBUG 6b6d09e8-2b6d-11f0-a582-fa163e36f7a6 2025-05-07T18:06:38Z DEBUG [] 2025-05-07T18:06:38Z DEBUG Updated 0 2025-05-07T18:06:38Z DEBUG Done 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=editors,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG posixgroup 2025-05-07T18:06:39Z DEBUG ipausergroup 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG nestedGroup 2025-05-07T18:06:39Z DEBUG gidNumber: 2025-05-07T18:06:39Z DEBUG 63800002 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG Limited admins who can edit other users 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG editors 2025-05-07T18:06:39Z DEBUG ipaUniqueID: 2025-05-07T18:06:39Z DEBUG 6b6f0b80-2b6d-11f0-9a72-fa163e36f7a6 2025-05-07T18:06:39Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'ipaobject', 'nestedGroup'] 2025-05-07T18:06:39Z DEBUG add: updated value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'nestedGroup', 'ipaobject'] 2025-05-07T18:06:39Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['6b6f0b80-2b6d-11f0-9a72-fa163e36f7a6'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG posixgroup 2025-05-07T18:06:39Z DEBUG ipausergroup 2025-05-07T18:06:39Z DEBUG nestedGroup 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG gidNumber: 2025-05-07T18:06:39Z DEBUG 63800002 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG Limited admins who can edit other users 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG editors 2025-05-07T18:06:39Z DEBUG ipaUniqueID: 2025-05-07T18:06:39Z DEBUG 6b6f0b80-2b6d-11f0-9a72-fa163e36f7a6 2025-05-07T18:06:39Z DEBUG [] 2025-05-07T18:06:39Z DEBUG Updated 0 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-groupuuid.update 0.117 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/50-hbacservice.update' 2025-05-07T18:06:39Z DEBUG New entry: cn=crond,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG crond 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG crond 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG crond 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG crond 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG New entry: cn=vsftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG vsftpd 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG vsftpd 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG vsftpd 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG vsftpd 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG New entry: cn=proftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG proftpd 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG proftpd 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG proftpd 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG proftpd 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG New entry: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG pure-ftpd 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG pure-ftpd 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG pure-ftpd 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG pure-ftpd 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG New entry: cn=gssftp,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG gssftp 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG gssftp 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG ipahbacservice 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG gssftp 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG gssftp 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG New entry: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipahbacservicegroup 2025-05-07T18:06:39Z DEBUG nestedGroup 2025-05-07T18:06:39Z DEBUG groupOfNames 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ftp 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG Default group of ftp related services 2025-05-07T18:06:39Z DEBUG member: 2025-05-07T18:06:39Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipahbacservicegroup 2025-05-07T18:06:39Z DEBUG nestedGroup 2025-05-07T18:06:39Z DEBUG groupOfNames 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ftp 2025-05-07T18:06:39Z DEBUG ipauniqueid: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG Default group of ftp related services 2025-05-07T18:06:39Z DEBUG member: 2025-05-07T18:06:39Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-hbacservice.update 0.185 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/50-ipaconfig.update' 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=ipaConfig,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG ipaGuiConfig 2025-05-07T18:06:39Z DEBUG ipaConfigObject 2025-05-07T18:06:39Z DEBUG ipaUserSearchFields: 2025-05-07T18:06:39Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2025-05-07T18:06:39Z DEBUG ipaGroupSearchFields: 2025-05-07T18:06:39Z DEBUG cn,description 2025-05-07T18:06:39Z DEBUG ipaSearchTimeLimit: 2025-05-07T18:06:39Z DEBUG 2 2025-05-07T18:06:39Z DEBUG ipaSearchRecordsLimit: 2025-05-07T18:06:39Z DEBUG 100 2025-05-07T18:06:39Z DEBUG ipaHomesRootDir: 2025-05-07T18:06:39Z DEBUG /home 2025-05-07T18:06:39Z DEBUG ipaDefaultLoginShell: 2025-05-07T18:06:39Z DEBUG /bin/sh 2025-05-07T18:06:39Z DEBUG ipaDefaultPrimaryGroup: 2025-05-07T18:06:39Z DEBUG ipausers 2025-05-07T18:06:39Z DEBUG ipaMaxUsernameLength: 2025-05-07T18:06:39Z DEBUG 32 2025-05-07T18:06:39Z DEBUG ipaMaxHostnameLength: 2025-05-07T18:06:39Z DEBUG 64 2025-05-07T18:06:39Z DEBUG ipaPwdExpAdvNotify: 2025-05-07T18:06:39Z DEBUG 4 2025-05-07T18:06:39Z DEBUG ipaGroupObjectClasses: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG nestedgroup 2025-05-07T18:06:39Z DEBUG ipausergroup 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipaUserObjectClasses: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG person 2025-05-07T18:06:39Z DEBUG organizationalperson 2025-05-07T18:06:39Z DEBUG inetorgperson 2025-05-07T18:06:39Z DEBUG inetuser 2025-05-07T18:06:39Z DEBUG posixaccount 2025-05-07T18:06:39Z DEBUG krbprincipalaux 2025-05-07T18:06:39Z DEBUG krbticketpolicyaux 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipasshuser 2025-05-07T18:06:39Z DEBUG ipaDefaultEmailDomain: 2025-05-07T18:06:39Z DEBUG ufreeipa.test 2025-05-07T18:06:39Z DEBUG ipaMigrationEnabled: 2025-05-07T18:06:39Z DEBUG FALSE 2025-05-07T18:06:39Z DEBUG ipaConfigString: 2025-05-07T18:06:39Z DEBUG AllowNThash 2025-05-07T18:06:39Z DEBUG KDC:Disable Last Success 2025-05-07T18:06:39Z DEBUG ipaSELinuxUserMapOrder: 2025-05-07T18:06:39Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2025-05-07T18:06:39Z DEBUG ipaSELinuxUserMapDefault: 2025-05-07T18:06:39Z DEBUG unconfined_u:s0-s0:c0.c1023 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ipaConfig 2025-05-07T18:06:39Z DEBUG ipaCertificateSubjectBase: 2025-05-07T18:06:39Z DEBUG O=UFREEIPA.TEST 2025-05-07T18:06:39Z DEBUG replace: guest_u:s0$$xguest_u:s0$$user_u:s0$$staff_u:s0-s0:c0.c1023$$sysadm_u:s0-s0:c0.c1023$$unconfined_u:s0-s0:c0.c1023 not found, skipping 2025-05-07T18:06:39Z DEBUG replace: ipaSELinuxUserMapOrder: guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 not found, skipping 2025-05-07T18:06:39Z DEBUG replace: guest_u:s0$xguest_u:s0$user_u:s0-s0:c0.c1023$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 not found, skipping 2025-05-07T18:06:39Z DEBUG add: 'unconfined_u:s0-s0:c0.c1023' to ipaSELinuxUserMapDefault, current value ['unconfined_u:s0-s0:c0.c1023'] 2025-05-07T18:06:39Z DEBUG add: updated value ['unconfined_u:s0-s0:c0.c1023'] 2025-05-07T18:06:39Z DEBUG add: 'ipasshuser' to ipaUserObjectClasses, current value ['top', 'person', 'organizationalperson', 'inetorgperson', 'inetuser', 'posixaccount', 'krbprincipalaux', 'krbticketpolicyaux', 'ipaobject', 'ipasshuser'] 2025-05-07T18:06:39Z DEBUG add: updated value ['top', 'person', 'organizationalperson', 'inetorgperson', 'inetuser', 'posixaccount', 'krbprincipalaux', 'krbticketpolicyaux', 'ipaobject', 'ipasshuser'] 2025-05-07T18:06:39Z DEBUG remove: 'AllowLMhash' from ipaConfigString, current value ['AllowNThash', 'KDC:Disable Last Success'] 2025-05-07T18:06:39Z DEBUG remove: 'AllowLMhash' not in ipaConfigString 2025-05-07T18:06:39Z DEBUG add: 'ipaUserAuthTypeClass' to objectClass, current value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject'] 2025-05-07T18:06:39Z DEBUG add: updated value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass'] 2025-05-07T18:06:39Z DEBUG add: 'ipaNameResolutionData' to objectClass, current value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass'] 2025-05-07T18:06:39Z DEBUG add: updated value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass', 'ipaNameResolutionData'] 2025-05-07T18:06:39Z DEBUG addifnew: '64' to ipamaxhostnamelength, current value ['64'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=ipaConfig,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG ipaGuiConfig 2025-05-07T18:06:39Z DEBUG ipaConfigObject 2025-05-07T18:06:39Z DEBUG ipaUserAuthTypeClass 2025-05-07T18:06:39Z DEBUG ipaNameResolutionData 2025-05-07T18:06:39Z DEBUG ipaUserSearchFields: 2025-05-07T18:06:39Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2025-05-07T18:06:39Z DEBUG ipaGroupSearchFields: 2025-05-07T18:06:39Z DEBUG cn,description 2025-05-07T18:06:39Z DEBUG ipaSearchTimeLimit: 2025-05-07T18:06:39Z DEBUG 2 2025-05-07T18:06:39Z DEBUG ipaSearchRecordsLimit: 2025-05-07T18:06:39Z DEBUG 100 2025-05-07T18:06:39Z DEBUG ipaHomesRootDir: 2025-05-07T18:06:39Z DEBUG /home 2025-05-07T18:06:39Z DEBUG ipaDefaultLoginShell: 2025-05-07T18:06:39Z DEBUG /bin/sh 2025-05-07T18:06:39Z DEBUG ipaDefaultPrimaryGroup: 2025-05-07T18:06:39Z DEBUG ipausers 2025-05-07T18:06:39Z DEBUG ipaMaxUsernameLength: 2025-05-07T18:06:39Z DEBUG 32 2025-05-07T18:06:39Z DEBUG ipaMaxHostnameLength: 2025-05-07T18:06:39Z DEBUG 64 2025-05-07T18:06:39Z DEBUG ipaPwdExpAdvNotify: 2025-05-07T18:06:39Z DEBUG 4 2025-05-07T18:06:39Z DEBUG ipaGroupObjectClasses: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG nestedgroup 2025-05-07T18:06:39Z DEBUG ipausergroup 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipaUserObjectClasses: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG person 2025-05-07T18:06:39Z DEBUG organizationalperson 2025-05-07T18:06:39Z DEBUG inetorgperson 2025-05-07T18:06:39Z DEBUG inetuser 2025-05-07T18:06:39Z DEBUG posixaccount 2025-05-07T18:06:39Z DEBUG krbprincipalaux 2025-05-07T18:06:39Z DEBUG krbticketpolicyaux 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipasshuser 2025-05-07T18:06:39Z DEBUG ipaDefaultEmailDomain: 2025-05-07T18:06:39Z DEBUG ufreeipa.test 2025-05-07T18:06:39Z DEBUG ipaMigrationEnabled: 2025-05-07T18:06:39Z DEBUG FALSE 2025-05-07T18:06:39Z DEBUG ipaConfigString: 2025-05-07T18:06:39Z DEBUG AllowNThash 2025-05-07T18:06:39Z DEBUG KDC:Disable Last Success 2025-05-07T18:06:39Z DEBUG ipaSELinuxUserMapOrder: 2025-05-07T18:06:39Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2025-05-07T18:06:39Z DEBUG ipaSELinuxUserMapDefault: 2025-05-07T18:06:39Z DEBUG unconfined_u:s0-s0:c0.c1023 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ipaConfig 2025-05-07T18:06:39Z DEBUG ipaCertificateSubjectBase: 2025-05-07T18:06:39Z DEBUG O=UFREEIPA.TEST 2025-05-07T18:06:39Z DEBUG [(0, 'objectClass', ['ipaUserAuthTypeClass', 'ipaNameResolutionData'])] 2025-05-07T18:06:39Z DEBUG Updated 1 2025-05-07T18:06:39Z DEBUG update_entry modlist [(0, 'objectClass', [b'ipaUserAuthTypeClass', b'ipaNameResolutionData'])] 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-ipaconfig.update 0.039 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/50-krbenctypes.update' 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG UFREEIPA.TEST 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG krbrealmcontainer 2025-05-07T18:06:39Z DEBUG krbticketpolicyaux 2025-05-07T18:06:39Z DEBUG krbSubTrees: 2025-05-07T18:06:39Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG krbSearchScope: 2025-05-07T18:06:39Z DEBUG 2 2025-05-07T18:06:39Z DEBUG krbSupportedEncSaltTypes: 2025-05-07T18:06:39Z DEBUG aes256-cts:normal 2025-05-07T18:06:39Z DEBUG aes256-cts:special 2025-05-07T18:06:39Z DEBUG aes128-cts:normal 2025-05-07T18:06:39Z DEBUG aes128-cts:special 2025-05-07T18:06:39Z DEBUG aes128-sha2:normal 2025-05-07T18:06:39Z DEBUG aes128-sha2:special 2025-05-07T18:06:39Z DEBUG aes256-sha2:normal 2025-05-07T18:06:39Z DEBUG aes256-sha2:special 2025-05-07T18:06:39Z DEBUG camellia128-cts-cmac:normal 2025-05-07T18:06:39Z DEBUG camellia128-cts-cmac:special 2025-05-07T18:06:39Z DEBUG camellia256-cts-cmac:normal 2025-05-07T18:06:39Z DEBUG camellia256-cts-cmac:special 2025-05-07T18:06:39Z DEBUG krbMaxTicketLife: 2025-05-07T18:06:39Z DEBUG 86400 2025-05-07T18:06:39Z DEBUG krbMaxRenewableAge: 2025-05-07T18:06:39Z DEBUG 604800 2025-05-07T18:06:39Z DEBUG krbDefaultEncSaltTypes: 2025-05-07T18:06:39Z DEBUG aes256-sha2:special 2025-05-07T18:06:39Z DEBUG aes128-sha2:special 2025-05-07T18:06:39Z DEBUG aes256-cts:special 2025-05-07T18:06:39Z DEBUG aes128-cts:special 2025-05-07T18:06:39Z DEBUG krbMKey: 2025-05-07T18:06:39Z DEBUG XXXXXXXX 2025-05-07T18:06:39Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:39Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG add: 'camellia128-cts-cmac:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2025-05-07T18:06:39Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal'] 2025-05-07T18:06:39Z DEBUG add: 'camellia128-cts-cmac:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal'] 2025-05-07T18:06:39Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special'] 2025-05-07T18:06:39Z DEBUG add: 'camellia256-cts-cmac:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special'] 2025-05-07T18:06:39Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal'] 2025-05-07T18:06:39Z DEBUG add: 'camellia256-cts-cmac:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal'] 2025-05-07T18:06:39Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2025-05-07T18:06:39Z DEBUG add: 'aes128-sha2:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2025-05-07T18:06:39Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal'] 2025-05-07T18:06:39Z DEBUG add: 'aes128-sha2:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal'] 2025-05-07T18:06:39Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special'] 2025-05-07T18:06:39Z DEBUG add: 'aes256-sha2:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special'] 2025-05-07T18:06:39Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal'] 2025-05-07T18:06:39Z DEBUG add: 'aes256-sha2:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal'] 2025-05-07T18:06:39Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special'] 2025-05-07T18:06:39Z DEBUG remove: 'des3-hmac-sha1:special' from krbDefaultEncSaltTypes, current value ['aes256-sha2:special', 'aes128-sha2:special', 'aes256-cts:special', 'aes128-cts:special'] 2025-05-07T18:06:39Z DEBUG remove: 'des3-hmac-sha1:special' not in krbDefaultEncSaltTypes 2025-05-07T18:06:39Z DEBUG remove: 'arcfour-hmac:special' from krbDefaultEncSaltTypes, current value ['aes256-sha2:special', 'aes128-sha2:special', 'aes256-cts:special', 'aes128-cts:special'] 2025-05-07T18:06:39Z DEBUG remove: 'arcfour-hmac:special' not in krbDefaultEncSaltTypes 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG UFREEIPA.TEST 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG krbrealmcontainer 2025-05-07T18:06:39Z DEBUG krbticketpolicyaux 2025-05-07T18:06:39Z DEBUG krbSubTrees: 2025-05-07T18:06:39Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG krbSearchScope: 2025-05-07T18:06:39Z DEBUG 2 2025-05-07T18:06:39Z DEBUG krbSupportedEncSaltTypes: 2025-05-07T18:06:39Z DEBUG aes256-cts:normal 2025-05-07T18:06:39Z DEBUG aes256-cts:special 2025-05-07T18:06:39Z DEBUG aes128-cts:normal 2025-05-07T18:06:39Z DEBUG aes128-cts:special 2025-05-07T18:06:39Z DEBUG camellia128-cts-cmac:normal 2025-05-07T18:06:39Z DEBUG camellia128-cts-cmac:special 2025-05-07T18:06:39Z DEBUG camellia256-cts-cmac:normal 2025-05-07T18:06:39Z DEBUG camellia256-cts-cmac:special 2025-05-07T18:06:39Z DEBUG aes128-sha2:normal 2025-05-07T18:06:39Z DEBUG aes128-sha2:special 2025-05-07T18:06:39Z DEBUG aes256-sha2:normal 2025-05-07T18:06:39Z DEBUG aes256-sha2:special 2025-05-07T18:06:39Z DEBUG krbMaxTicketLife: 2025-05-07T18:06:39Z DEBUG 86400 2025-05-07T18:06:39Z DEBUG krbMaxRenewableAge: 2025-05-07T18:06:39Z DEBUG 604800 2025-05-07T18:06:39Z DEBUG krbDefaultEncSaltTypes: 2025-05-07T18:06:39Z DEBUG aes256-sha2:special 2025-05-07T18:06:39Z DEBUG aes128-sha2:special 2025-05-07T18:06:39Z DEBUG aes256-cts:special 2025-05-07T18:06:39Z DEBUG aes128-cts:special 2025-05-07T18:06:39Z DEBUG krbMKey: 2025-05-07T18:06:39Z DEBUG XXXXXXXX 2025-05-07T18:06:39Z DEBUG krbPwdPolicyReference: 2025-05-07T18:06:39Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=UFREEIPA.TEST,cn=kerberos,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG [] 2025-05-07T18:06:39Z DEBUG Updated 0 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-krbenctypes.update 0.009 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/55-pbacmemberof.update' 2025-05-07T18:06:39Z DEBUG New entry: cn=Update PBAC memberOf 139659339,cn=memberof task,cn=tasks,cn=config 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=Update PBAC memberOf 139659339,cn=memberof task,cn=tasks,cn=config 2025-05-07T18:06:39Z DEBUG add: 'top' to objectClass, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['top'] 2025-05-07T18:06:39Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2025-05-07T18:06:39Z DEBUG add: updated value ['top', 'extensibleObject'] 2025-05-07T18:06:39Z DEBUG add: 'IPA PBAC memberOf 139659339' to cn, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['IPA PBAC memberOf 139659339'] 2025-05-07T18:06:39Z DEBUG add: 'cn=privileges,cn=pbac,dc=ufreeipa,dc=test' to basedn, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['cn=privileges,cn=pbac,dc=ufreeipa,dc=test'] 2025-05-07T18:06:39Z DEBUG add: '(objectclass=*)' to filter, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['(objectclass=*)'] 2025-05-07T18:06:39Z DEBUG add: '10' to ttl, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['10'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=Update PBAC memberOf 139659339,cn=memberof task,cn=tasks,cn=config 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG extensibleObject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG IPA PBAC memberOf 139659339 2025-05-07T18:06:39Z DEBUG basedn: 2025-05-07T18:06:39Z DEBUG cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG filter: 2025-05-07T18:06:39Z DEBUG (objectclass=*) 2025-05-07T18:06:39Z DEBUG ttl: 2025-05-07T18:06:39Z DEBUG 10 2025-05-07T18:06:39Z DEBUG New entry: cn=Update Role memberOf 139659339,cn=memberof task,cn=tasks,cn=config 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=Update Role memberOf 139659339,cn=memberof task,cn=tasks,cn=config 2025-05-07T18:06:39Z DEBUG add: 'top' to objectClass, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['top'] 2025-05-07T18:06:39Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2025-05-07T18:06:39Z DEBUG add: updated value ['top', 'extensibleObject'] 2025-05-07T18:06:39Z DEBUG add: 'Update Role memberOf 139659339' to cn, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['Update Role memberOf 139659339'] 2025-05-07T18:06:39Z DEBUG add: 'cn=roles,cn=accounts,dc=ufreeipa,dc=test' to basedn, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['cn=roles,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:06:39Z DEBUG add: '(objectclass=*)' to filter, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['(objectclass=*)'] 2025-05-07T18:06:39Z DEBUG add: '10' to ttl, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['10'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=Update Role memberOf 139659339,cn=memberof task,cn=tasks,cn=config 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG extensibleObject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG Update Role memberOf 139659339 2025-05-07T18:06:39Z DEBUG basedn: 2025-05-07T18:06:39Z DEBUG cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG filter: 2025-05-07T18:06:39Z DEBUG (objectclass=*) 2025-05-07T18:06:39Z DEBUG ttl: 2025-05-07T18:06:39Z DEBUG 10 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/55-pbacmemberof.update 0.107 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/59-trusts-sysacount.update' 2025-05-07T18:06:39Z DEBUG New entry: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG GroupOfNames 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG adtrust agents 2025-05-07T18:06:39Z DEBUG add: 'nestedgroup' to objectClass, current value ['GroupOfNames', 'top'] 2025-05-07T18:06:39Z DEBUG add: updated value ['GroupOfNames', 'top', 'nestedgroup'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG GroupOfNames 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nestedgroup 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG adtrust agents 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/59-trusts-sysacount.update 0.055 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/60-trusts.update' 2025-05-07T18:06:39Z DEBUG New entry: cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG ipausergroup 2025-05-07T18:06:39Z DEBUG nestedgroup 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG trust admins 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG Trusts administrators group 2025-05-07T18:06:39Z DEBUG member: 2025-05-07T18:06:39Z DEBUG uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG nsAccountLock: 2025-05-07T18:06:39Z DEBUG FALSE 2025-05-07T18:06:39Z DEBUG ipaUniqueID: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG ipausergroup 2025-05-07T18:06:39Z DEBUG nestedgroup 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG trust admins 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG Trusts administrators group 2025-05-07T18:06:39Z DEBUG member: 2025-05-07T18:06:39Z DEBUG uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG nsAccountLock: 2025-05-07T18:06:39Z DEBUG FALSE 2025-05-07T18:06:39Z DEBUG ipaUniqueID: 2025-05-07T18:06:39Z DEBUG autogenerate 2025-05-07T18:06:39Z DEBUG New entry: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG nestedgroup 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ADTrust Agents 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG System accounts able to access trust information 2025-05-07T18:06:39Z DEBUG member: 2025-05-07T18:06:39Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG nestedgroup 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ADTrust Agents 2025-05-07T18:06:39Z DEBUG description: 2025-05-07T18:06:39Z DEBUG System accounts able to access trust information 2025-05-07T18:06:39Z DEBUG member: 2025-05-07T18:06:39Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG New entry: cn=trusts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=trusts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG trusts 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=trusts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG trusts 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=trusts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=trusts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG trusts 2025-05-07T18:06:39Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2025-05-07T18:06:39Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2025-05-07T18:06:39Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG add: '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG replace: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG replace: (target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) not found, skipping 2025-05-07T18:06:39Z DEBUG add: '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG add: '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=trusts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG trusts 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG [(2, 'aci', ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:39Z DEBUG Updated 1 2025-05-07T18:06:39Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', b'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', b'(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', b'(target = "ldap:///cn=trusts,dc=ufreeipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', b'(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG domain 2025-05-07T18:06:39Z DEBUG pilotObject 2025-05-07T18:06:39Z DEBUG domainRelatedObject 2025-05-07T18:06:39Z DEBUG nisDomainObject 2025-05-07T18:06:39Z DEBUG dc: 2025-05-07T18:06:39Z DEBUG ufreeipa 2025-05-07T18:06:39Z DEBUG info: 2025-05-07T18:06:39Z DEBUG IPA V2.0 2025-05-07T18:06:39Z DEBUG associatedDomain: 2025-05-07T18:06:39Z DEBUG ufreeipa.test 2025-05-07T18:06:39Z DEBUG nisDomain: 2025-05-07T18:06:39Z DEBUG ufreeipa.test 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:39Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:39Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:39Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:39Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG add: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)' not in aci 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG domain 2025-05-07T18:06:39Z DEBUG pilotObject 2025-05-07T18:06:39Z DEBUG domainRelatedObject 2025-05-07T18:06:39Z DEBUG nisDomainObject 2025-05-07T18:06:39Z DEBUG dc: 2025-05-07T18:06:39Z DEBUG ufreeipa 2025-05-07T18:06:39Z DEBUG info: 2025-05-07T18:06:39Z DEBUG IPA V2.0 2025-05-07T18:06:39Z DEBUG associatedDomain: 2025-05-07T18:06:39Z DEBUG ufreeipa.test 2025-05-07T18:06:39Z DEBUG nisDomain: 2025-05-07T18:06:39Z DEBUG ufreeipa.test 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:39Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:39Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:39Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:39Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:39Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:39Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG [(0, 'aci', ['(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:39Z DEBUG Updated 1 2025-05-07T18:06:39Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG accounts 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2025-05-07T18:06:39Z DEBUG add: '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2025-05-07T18:06:39Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG accounts 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2025-05-07T18:06:39Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2025-05-07T18:06:39Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2025-05-07T18:06:39Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:39Z DEBUG Updated 1 2025-05-07T18:06:39Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG services 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:39Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG add: '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:39Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)'] 2025-05-07T18:06:39Z DEBUG add: '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)'] 2025-05-07T18:06:39Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=services,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG services 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ufreeipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2025-05-07T18:06:39Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";) 2025-05-07T18:06:39Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";) 2025-05-07T18:06:39Z DEBUG [(0, 'aci', ['(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)'])] 2025-05-07T18:06:39Z DEBUG Updated 1 2025-05-07T18:06:39Z DEBUG update_entry modlist [(0, 'aci', [b'(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)', b'(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ufreeipa,dc=test" or userattr="managedby#SELFDN";)'])] 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=ipaConfig,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG ipaGuiConfig 2025-05-07T18:06:39Z DEBUG ipaConfigObject 2025-05-07T18:06:39Z DEBUG ipaUserAuthTypeClass 2025-05-07T18:06:39Z DEBUG ipaNameResolutionData 2025-05-07T18:06:39Z DEBUG ipaUserSearchFields: 2025-05-07T18:06:39Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2025-05-07T18:06:39Z DEBUG ipaGroupSearchFields: 2025-05-07T18:06:39Z DEBUG cn,description 2025-05-07T18:06:39Z DEBUG ipaSearchTimeLimit: 2025-05-07T18:06:39Z DEBUG 2 2025-05-07T18:06:39Z DEBUG ipaSearchRecordsLimit: 2025-05-07T18:06:39Z DEBUG 100 2025-05-07T18:06:39Z DEBUG ipaHomesRootDir: 2025-05-07T18:06:39Z DEBUG /home 2025-05-07T18:06:39Z DEBUG ipaDefaultLoginShell: 2025-05-07T18:06:39Z DEBUG /bin/sh 2025-05-07T18:06:39Z DEBUG ipaDefaultPrimaryGroup: 2025-05-07T18:06:39Z DEBUG ipausers 2025-05-07T18:06:39Z DEBUG ipaMaxUsernameLength: 2025-05-07T18:06:39Z DEBUG 32 2025-05-07T18:06:39Z DEBUG ipaMaxHostnameLength: 2025-05-07T18:06:39Z DEBUG 64 2025-05-07T18:06:39Z DEBUG ipaPwdExpAdvNotify: 2025-05-07T18:06:39Z DEBUG 4 2025-05-07T18:06:39Z DEBUG ipaGroupObjectClasses: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG nestedgroup 2025-05-07T18:06:39Z DEBUG ipausergroup 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipaUserObjectClasses: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG person 2025-05-07T18:06:39Z DEBUG organizationalperson 2025-05-07T18:06:39Z DEBUG inetorgperson 2025-05-07T18:06:39Z DEBUG inetuser 2025-05-07T18:06:39Z DEBUG posixaccount 2025-05-07T18:06:39Z DEBUG krbprincipalaux 2025-05-07T18:06:39Z DEBUG krbticketpolicyaux 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipasshuser 2025-05-07T18:06:39Z DEBUG ipaDefaultEmailDomain: 2025-05-07T18:06:39Z DEBUG ufreeipa.test 2025-05-07T18:06:39Z DEBUG ipaMigrationEnabled: 2025-05-07T18:06:39Z DEBUG FALSE 2025-05-07T18:06:39Z DEBUG ipaConfigString: 2025-05-07T18:06:39Z DEBUG AllowNThash 2025-05-07T18:06:39Z DEBUG KDC:Disable Last Success 2025-05-07T18:06:39Z DEBUG ipaSELinuxUserMapOrder: 2025-05-07T18:06:39Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2025-05-07T18:06:39Z DEBUG ipaSELinuxUserMapDefault: 2025-05-07T18:06:39Z DEBUG unconfined_u:s0-s0:c0.c1023 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ipaConfig 2025-05-07T18:06:39Z DEBUG ipaCertificateSubjectBase: 2025-05-07T18:06:39Z DEBUG O=UFREEIPA.TEST 2025-05-07T18:06:39Z DEBUG add: 'MS-PAC' to ipaKrbAuthzData, current value [] 2025-05-07T18:06:39Z DEBUG add: updated value ['MS-PAC'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=ipaConfig,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG ipaGuiConfig 2025-05-07T18:06:39Z DEBUG ipaConfigObject 2025-05-07T18:06:39Z DEBUG ipaUserAuthTypeClass 2025-05-07T18:06:39Z DEBUG ipaNameResolutionData 2025-05-07T18:06:39Z DEBUG ipaUserSearchFields: 2025-05-07T18:06:39Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2025-05-07T18:06:39Z DEBUG ipaGroupSearchFields: 2025-05-07T18:06:39Z DEBUG cn,description 2025-05-07T18:06:39Z DEBUG ipaSearchTimeLimit: 2025-05-07T18:06:39Z DEBUG 2 2025-05-07T18:06:39Z DEBUG ipaSearchRecordsLimit: 2025-05-07T18:06:39Z DEBUG 100 2025-05-07T18:06:39Z DEBUG ipaHomesRootDir: 2025-05-07T18:06:39Z DEBUG /home 2025-05-07T18:06:39Z DEBUG ipaDefaultLoginShell: 2025-05-07T18:06:39Z DEBUG /bin/sh 2025-05-07T18:06:39Z DEBUG ipaDefaultPrimaryGroup: 2025-05-07T18:06:39Z DEBUG ipausers 2025-05-07T18:06:39Z DEBUG ipaMaxUsernameLength: 2025-05-07T18:06:39Z DEBUG 32 2025-05-07T18:06:39Z DEBUG ipaMaxHostnameLength: 2025-05-07T18:06:39Z DEBUG 64 2025-05-07T18:06:39Z DEBUG ipaPwdExpAdvNotify: 2025-05-07T18:06:39Z DEBUG 4 2025-05-07T18:06:39Z DEBUG ipaGroupObjectClasses: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG groupofnames 2025-05-07T18:06:39Z DEBUG nestedgroup 2025-05-07T18:06:39Z DEBUG ipausergroup 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipaUserObjectClasses: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG person 2025-05-07T18:06:39Z DEBUG organizationalperson 2025-05-07T18:06:39Z DEBUG inetorgperson 2025-05-07T18:06:39Z DEBUG inetuser 2025-05-07T18:06:39Z DEBUG posixaccount 2025-05-07T18:06:39Z DEBUG krbprincipalaux 2025-05-07T18:06:39Z DEBUG krbticketpolicyaux 2025-05-07T18:06:39Z DEBUG ipaobject 2025-05-07T18:06:39Z DEBUG ipasshuser 2025-05-07T18:06:39Z DEBUG ipaDefaultEmailDomain: 2025-05-07T18:06:39Z DEBUG ufreeipa.test 2025-05-07T18:06:39Z DEBUG ipaMigrationEnabled: 2025-05-07T18:06:39Z DEBUG FALSE 2025-05-07T18:06:39Z DEBUG ipaConfigString: 2025-05-07T18:06:39Z DEBUG AllowNThash 2025-05-07T18:06:39Z DEBUG KDC:Disable Last Success 2025-05-07T18:06:39Z DEBUG ipaSELinuxUserMapOrder: 2025-05-07T18:06:39Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2025-05-07T18:06:39Z DEBUG ipaSELinuxUserMapDefault: 2025-05-07T18:06:39Z DEBUG unconfined_u:s0-s0:c0.c1023 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ipaConfig 2025-05-07T18:06:39Z DEBUG ipaCertificateSubjectBase: 2025-05-07T18:06:39Z DEBUG O=UFREEIPA.TEST 2025-05-07T18:06:39Z DEBUG ipaKrbAuthzData: 2025-05-07T18:06:39Z DEBUG MS-PAC 2025-05-07T18:06:39Z DEBUG [(2, 'ipaKrbAuthzData', ['MS-PAC'])] 2025-05-07T18:06:39Z DEBUG Updated 1 2025-05-07T18:06:39Z DEBUG update_entry modlist [(2, 'ipaKrbAuthzData', [b'MS-PAC'])] 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/60-trusts.update 0.268 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/61-trusts-s4u2proxy.update' 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG groupOfPrincipals 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ipa-cifs-delegation-targets 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG groupOfPrincipals 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ipa-cifs-delegation-targets 2025-05-07T18:06:39Z DEBUG [] 2025-05-07T18:06:39Z DEBUG Updated 0 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG ipaKrb5DelegationACL 2025-05-07T18:06:39Z DEBUG groupOfPrincipals 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ipa-http-delegation 2025-05-07T18:06:39Z DEBUG memberPrincipal: 2025-05-07T18:06:39Z DEBUG HTTP/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:39Z DEBUG ipaAllowedTarget: 2025-05-07T18:06:39Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG add: 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test' to ipaAllowedTarget, current value ['cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test', 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:39Z DEBUG add: updated value ['cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test', 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG ipaKrb5DelegationACL 2025-05-07T18:06:39Z DEBUG groupOfPrincipals 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ipa-http-delegation 2025-05-07T18:06:39Z DEBUG memberPrincipal: 2025-05-07T18:06:39Z DEBUG HTTP/master.ufreeipa.test@UFREEIPA.TEST 2025-05-07T18:06:39Z DEBUG ipaAllowedTarget: 2025-05-07T18:06:39Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG [] 2025-05-07T18:06:39Z DEBUG Updated 0 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/61-trusts-s4u2proxy.update 0.033 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/62-ranges.update' 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=ranges,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ranges 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=ranges,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ranges 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@UFREEIPA.TEST,cn=services,cn=accounts,dc=ufreeipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG [] 2025-05-07T18:06:39Z DEBUG Updated 0 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=IPA Range-Check,cn=plugins,cn=config 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG IPA Range-Check 2025-05-07T18:06:39Z DEBUG nsslapd-basedn: 2025-05-07T18:06:39Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:39Z DEBUG database 2025-05-07T18:06:39Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:39Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2025-05-07T18:06:39Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:39Z DEBUG on 2025-05-07T18:06:39Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:39Z DEBUG IPA ID range check plugin 2025-05-07T18:06:39Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:39Z DEBUG ipa_range_check_init 2025-05-07T18:06:39Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:39Z DEBUG libipa_range_check 2025-05-07T18:06:39Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:39Z DEBUG preoperation 2025-05-07T18:06:39Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:39Z DEBUG FreeIPA project 2025-05-07T18:06:39Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:39Z DEBUG FreeIPA/1.0 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsSlapdPlugin 2025-05-07T18:06:39Z DEBUG extensibleObject 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG IPA Range-Check 2025-05-07T18:06:39Z DEBUG nsslapd-basedn: 2025-05-07T18:06:39Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:39Z DEBUG database 2025-05-07T18:06:39Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:39Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2025-05-07T18:06:39Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:39Z DEBUG on 2025-05-07T18:06:39Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:39Z DEBUG IPA ID range check plugin 2025-05-07T18:06:39Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:39Z DEBUG ipa_range_check_init 2025-05-07T18:06:39Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:39Z DEBUG libipa_range_check 2025-05-07T18:06:39Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:39Z DEBUG preoperation 2025-05-07T18:06:39Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:39Z DEBUG FreeIPA project 2025-05-07T18:06:39Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:39Z DEBUG FreeIPA/1.0 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsSlapdPlugin 2025-05-07T18:06:39Z DEBUG extensibleObject 2025-05-07T18:06:39Z DEBUG [] 2025-05-07T18:06:39Z DEBUG Updated 0 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG Posix IDs 2025-05-07T18:06:39Z DEBUG dnaExcludeScope: 2025-05-07T18:06:39Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG dnaFilter: 2025-05-07T18:06:39Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2025-05-07T18:06:39Z DEBUG dnaMagicRegen: 2025-05-07T18:06:39Z DEBUG -1 2025-05-07T18:06:39Z DEBUG dnaMaxValue: 2025-05-07T18:06:39Z DEBUG 63999999 2025-05-07T18:06:39Z DEBUG dnaNextValue: 2025-05-07T18:06:39Z DEBUG 63800000 2025-05-07T18:06:39Z DEBUG dnaScope: 2025-05-07T18:06:39Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG dnaSharedCfgDN: 2025-05-07T18:06:39Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG dnaThreshold: 2025-05-07T18:06:39Z DEBUG 500 2025-05-07T18:06:39Z DEBUG dnaType: 2025-05-07T18:06:39Z DEBUG uidNumber 2025-05-07T18:06:39Z DEBUG gidNumber 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG extensibleObject 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG replace: (|(objectclass=posixAccount)(objectClass=posixGroup)) not found, skipping 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG Posix IDs 2025-05-07T18:06:39Z DEBUG dnaExcludeScope: 2025-05-07T18:06:39Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG dnaFilter: 2025-05-07T18:06:39Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2025-05-07T18:06:39Z DEBUG dnaMagicRegen: 2025-05-07T18:06:39Z DEBUG -1 2025-05-07T18:06:39Z DEBUG dnaMaxValue: 2025-05-07T18:06:39Z DEBUG 63999999 2025-05-07T18:06:39Z DEBUG dnaNextValue: 2025-05-07T18:06:39Z DEBUG 63800000 2025-05-07T18:06:39Z DEBUG dnaScope: 2025-05-07T18:06:39Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG dnaSharedCfgDN: 2025-05-07T18:06:39Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG dnaThreshold: 2025-05-07T18:06:39Z DEBUG 500 2025-05-07T18:06:39Z DEBUG dnaType: 2025-05-07T18:06:39Z DEBUG uidNumber 2025-05-07T18:06:39Z DEBUG gidNumber 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG extensibleObject 2025-05-07T18:06:39Z DEBUG aci: 2025-05-07T18:06:39Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG (targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:39Z DEBUG [] 2025-05-07T18:06:39Z DEBUG Updated 0 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/62-ranges.update 0.017 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews-sasl-mapping.update' 2025-05-07T18:06:39Z DEBUG New entry: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ID Overridden Principal 2025-05-07T18:06:39Z DEBUG nsSaslMapBaseDNTemplate: 2025-05-07T18:06:39Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG nsSaslMapFilterTemplate: 2025-05-07T18:06:39Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2025-05-07T18:06:39Z DEBUG nsSaslMapPriority: 2025-05-07T18:06:39Z DEBUG 20 2025-05-07T18:06:39Z DEBUG nsSaslMapRegexString: 2025-05-07T18:06:39Z DEBUG \(.*\)@\(.*\) 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsSaslMapping 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG ID Overridden Principal 2025-05-07T18:06:39Z DEBUG nsSaslMapBaseDNTemplate: 2025-05-07T18:06:39Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG nsSaslMapFilterTemplate: 2025-05-07T18:06:39Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2025-05-07T18:06:39Z DEBUG nsSaslMapPriority: 2025-05-07T18:06:39Z DEBUG 20 2025-05-07T18:06:39Z DEBUG nsSaslMapRegexString: 2025-05-07T18:06:39Z DEBUG \(.*\)@\(.*\) 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsSaslMapping 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/71-idviews-sasl-mapping.update 0.020 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews.update' 2025-05-07T18:06:39Z DEBUG New entry: cn=views,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=views,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG views 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=views,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG views 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/71-idviews.update 0.020 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/72-domainlevels.update' 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=Domain Level,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG ipaDomainLevelConfig 2025-05-07T18:06:39Z DEBUG ipaConfigObject 2025-05-07T18:06:39Z DEBUG ipaDomainLevel: 2025-05-07T18:06:39Z DEBUG 1 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG Domain Level 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG ipaDomainLevelConfig 2025-05-07T18:06:39Z DEBUG ipaConfigObject 2025-05-07T18:06:39Z DEBUG ipaDomainLevel: 2025-05-07T18:06:39Z DEBUG 1 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG Domain Level 2025-05-07T18:06:39Z DEBUG [] 2025-05-07T18:06:39Z DEBUG Updated 0 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG Updating existing entry: cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG ipaReplTopoManagedServer 2025-05-07T18:06:39Z DEBUG ipaConfigObject 2025-05-07T18:06:39Z DEBUG ipaSupportedDomainLevelConfig 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG master.ufreeipa.test 2025-05-07T18:06:39Z DEBUG ipaReplTopoManagedSuffix: 2025-05-07T18:06:39Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG ipaMinDomainLevel: 2025-05-07T18:06:39Z DEBUG 1 2025-05-07T18:06:39Z DEBUG ipaMaxDomainLevel: 2025-05-07T18:06:39Z DEBUG 1 2025-05-07T18:06:39Z DEBUG add: 'ipaConfigObject' to objectClass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2025-05-07T18:06:39Z DEBUG add: updated value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaSupportedDomainLevelConfig', 'ipaConfigObject'] 2025-05-07T18:06:39Z DEBUG add: 'ipaSupportedDomainLevelConfig' to objectClass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaSupportedDomainLevelConfig', 'ipaConfigObject'] 2025-05-07T18:06:39Z DEBUG add: updated value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2025-05-07T18:06:39Z DEBUG only: set ipaMinDomainLevel to '1', current value ['1'] 2025-05-07T18:06:39Z DEBUG only: updated value ['1'] 2025-05-07T18:06:39Z DEBUG only: set ipaMaxDomainLevel to '1', current value ['1'] 2025-05-07T18:06:39Z DEBUG only: updated value ['1'] 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectClass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG ipaReplTopoManagedServer 2025-05-07T18:06:39Z DEBUG ipaConfigObject 2025-05-07T18:06:39Z DEBUG ipaSupportedDomainLevelConfig 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG master.ufreeipa.test 2025-05-07T18:06:39Z DEBUG ipaReplTopoManagedSuffix: 2025-05-07T18:06:39Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG ipaMinDomainLevel: 2025-05-07T18:06:39Z DEBUG 1 2025-05-07T18:06:39Z DEBUG ipaMaxDomainLevel: 2025-05-07T18:06:39Z DEBUG 1 2025-05-07T18:06:39Z DEBUG [] 2025-05-07T18:06:39Z DEBUG Updated 0 2025-05-07T18:06:39Z DEBUG Done 2025-05-07T18:06:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/72-domainlevels.update 0.018 sec 2025-05-07T18:06:39Z DEBUG Parsing update file '/usr/share/ipa/updates/73-certmap.update' 2025-05-07T18:06:39Z DEBUG New entry: cn=certmap,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=certmap,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG ipaCertMapConfigObject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG certmap 2025-05-07T18:06:39Z DEBUG ipaCertMapPromptUsername: 2025-05-07T18:06:39Z DEBUG FALSE 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=certmap,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG ipaCertMapConfigObject 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG certmap 2025-05-07T18:06:39Z DEBUG ipaCertMapPromptUsername: 2025-05-07T18:06:39Z DEBUG FALSE 2025-05-07T18:06:39Z DEBUG New entry: cn=certmaprules,cn=certmap,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Initial value 2025-05-07T18:06:39Z DEBUG dn: cn=certmaprules,cn=certmap,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG certmaprules 2025-05-07T18:06:39Z DEBUG --------------------------------------------- 2025-05-07T18:06:39Z DEBUG Final value after applying updates 2025-05-07T18:06:39Z DEBUG dn: cn=certmaprules,cn=certmap,dc=ufreeipa,dc=test 2025-05-07T18:06:39Z DEBUG objectclass: 2025-05-07T18:06:39Z DEBUG top 2025-05-07T18:06:39Z DEBUG nsContainer 2025-05-07T18:06:39Z DEBUG cn: 2025-05-07T18:06:39Z DEBUG certmaprules 2025-05-07T18:06:40Z DEBUG New entry: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Certificate Identity Mapping Administrators 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG Certificate Identity Mapping Administrators 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Certificate Identity Mapping Administrators 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG Certificate Identity Mapping Administrators 2025-05-07T18:06:40Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG domain 2025-05-07T18:06:40Z DEBUG pilotObject 2025-05-07T18:06:40Z DEBUG domainRelatedObject 2025-05-07T18:06:40Z DEBUG nisDomainObject 2025-05-07T18:06:40Z DEBUG dc: 2025-05-07T18:06:40Z DEBUG ufreeipa 2025-05-07T18:06:40Z DEBUG info: 2025-05-07T18:06:40Z DEBUG IPA V2.0 2025-05-07T18:06:40Z DEBUG associatedDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG nisDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG add: '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG domain 2025-05-07T18:06:40Z DEBUG pilotObject 2025-05-07T18:06:40Z DEBUG domainRelatedObject 2025-05-07T18:06:40Z DEBUG nisDomainObject 2025-05-07T18:06:40Z DEBUG dc: 2025-05-07T18:06:40Z DEBUG ufreeipa 2025-05-07T18:06:40Z DEBUG info: 2025-05-07T18:06:40Z DEBUG IPA V2.0 2025-05-07T18:06:40Z DEBUG associatedDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG nisDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG [(0, 'aci', ['(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'])] 2025-05-07T18:06:40Z DEBUG Updated 1 2025-05-07T18:06:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'])] 2025-05-07T18:06:40Z DEBUG Done 2025-05-07T18:06:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-certmap.update 0.488 sec 2025-05-07T18:06:40Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2025-05-07T18:06:40Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG custodia 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG custodia 2025-05-07T18:06:40Z DEBUG [] 2025-05-07T18:06:40Z DEBUG Updated 0 2025-05-07T18:06:40Z DEBUG Done 2025-05-07T18:06:40Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG dogtag 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG dogtag 2025-05-07T18:06:40Z DEBUG [] 2025-05-07T18:06:40Z DEBUG Updated 0 2025-05-07T18:06:40Z DEBUG Done 2025-05-07T18:06:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-custodia.update 0.013 sec 2025-05-07T18:06:40Z DEBUG Parsing update file '/usr/share/ipa/updates/73-passkey.update' 2025-05-07T18:06:40Z DEBUG New entry: cn=passkeyconfig,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=passkeyconfig,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectclass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nscontainer 2025-05-07T18:06:40Z DEBUG ipaPasskeyConfigObject 2025-05-07T18:06:40Z DEBUG ipaRequireUserVerification: 2025-05-07T18:06:40Z DEBUG TRUE 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=passkeyconfig,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectclass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nscontainer 2025-05-07T18:06:40Z DEBUG ipaPasskeyConfigObject 2025-05-07T18:06:40Z DEBUG ipaRequireUserVerification: 2025-05-07T18:06:40Z DEBUG TRUE 2025-05-07T18:06:40Z DEBUG New entry: cn=Passkey Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=Passkey Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Passkey Administrators 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG Passkey Administrators 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=Passkey Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Passkey Administrators 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG Passkey Administrators 2025-05-07T18:06:40Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG domain 2025-05-07T18:06:40Z DEBUG pilotObject 2025-05-07T18:06:40Z DEBUG domainRelatedObject 2025-05-07T18:06:40Z DEBUG nisDomainObject 2025-05-07T18:06:40Z DEBUG dc: 2025-05-07T18:06:40Z DEBUG ufreeipa 2025-05-07T18:06:40Z DEBUG info: 2025-05-07T18:06:40Z DEBUG IPA V2.0 2025-05-07T18:06:40Z DEBUG associatedDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG nisDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG add: '(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'] 2025-05-07T18:06:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)'] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG domain 2025-05-07T18:06:40Z DEBUG pilotObject 2025-05-07T18:06:40Z DEBUG domainRelatedObject 2025-05-07T18:06:40Z DEBUG nisDomainObject 2025-05-07T18:06:40Z DEBUG dc: 2025-05-07T18:06:40Z DEBUG ufreeipa 2025-05-07T18:06:40Z DEBUG info: 2025-05-07T18:06:40Z DEBUG IPA V2.0 2025-05-07T18:06:40Z DEBUG associatedDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG nisDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG [(0, 'aci', ['(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)'])] 2025-05-07T18:06:40Z DEBUG Updated 1 2025-05-07T18:06:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)'])] 2025-05-07T18:06:40Z DEBUG Done 2025-05-07T18:06:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-passkey.update 0.085 sec 2025-05-07T18:06:40Z DEBUG Parsing update file '/usr/share/ipa/updates/73-service-rbcd.update' 2025-05-07T18:06:40Z DEBUG Updating existing entry: dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG domain 2025-05-07T18:06:40Z DEBUG pilotObject 2025-05-07T18:06:40Z DEBUG domainRelatedObject 2025-05-07T18:06:40Z DEBUG nisDomainObject 2025-05-07T18:06:40Z DEBUG dc: 2025-05-07T18:06:40Z DEBUG ufreeipa 2025-05-07T18:06:40Z DEBUG info: 2025-05-07T18:06:40Z DEBUG IPA V2.0 2025-05-07T18:06:40Z DEBUG associatedDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG nisDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG add: '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Kerberos principals can manage resource-based constrained delegation for themselves";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)'] 2025-05-07T18:06:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Kerberos principals can manage resource-based constrained delegation for themselves";allow (write) userdn = "ldap:///self";)'] 2025-05-07T18:06:40Z DEBUG add: '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Managing principals can manage resource-based constrained delegation for other principals";allow (write) userattr = "managedby#GROUPDN" or userattr = "managedby#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Kerberos principals can manage resource-based constrained delegation for themselves";allow (write) userdn = "ldap:///self";)'] 2025-05-07T18:06:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Kerberos principals can manage resource-based constrained delegation for themselves";allow (write) userdn = "ldap:///self";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Managing principals can manage resource-based constrained delegation for other principals";allow (write) userattr = "managedby#GROUPDN" or userattr = "managedby#USERDN";)'] 2025-05-07T18:06:40Z DEBUG add: '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Delegated permission to manage resource-based constrained delegation for other principals";allow (write) userattr="ipaAllowedToPerform;write_delegation#GROUPDN" or userattr="ipaAllowedToPerform;write_delegation#USERDN" ;)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Kerberos principals can manage resource-based constrained delegation for themselves";allow (write) userdn = "ldap:///self";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Managing principals can manage resource-based constrained delegation for other principals";allow (write) userattr = "managedby#GROUPDN" or userattr = "managedby#USERDN";)'] 2025-05-07T18:06:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Kerberos principals can manage resource-based constrained delegation for themselves";allow (write) userdn = "ldap:///self";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Managing principals can manage resource-based constrained delegation for other principals";allow (write) userattr = "managedby#GROUPDN" or userattr = "managedby#USERDN";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Delegated permission to manage resource-based constrained delegation for other principals";allow (write) userattr="ipaAllowedToPerform;write_delegation#GROUPDN" or userattr="ipaAllowedToPerform;write_delegation#USERDN" ;)'] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG domain 2025-05-07T18:06:40Z DEBUG pilotObject 2025-05-07T18:06:40Z DEBUG domainRelatedObject 2025-05-07T18:06:40Z DEBUG nisDomainObject 2025-05-07T18:06:40Z DEBUG dc: 2025-05-07T18:06:40Z DEBUG ufreeipa 2025-05-07T18:06:40Z DEBUG info: 2025-05-07T18:06:40Z DEBUG IPA V2.0 2025-05-07T18:06:40Z DEBUG associatedDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG nisDomain: 2025-05-07T18:06:40Z DEBUG ufreeipa.test 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2025-05-07T18:06:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ufreeipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2025-05-07T18:06:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2025-05-07T18:06:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ufreeipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ufreeipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipapasskey")(targattrfilters="add=objectclass:(objectclass=ipapasskeyuser)")(version 3.0;acl "selfservice:Users can manage their own passkey mappings";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Kerberos principals can manage resource-based constrained delegation for themselves";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG (targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Managing principals can manage resource-based constrained delegation for other principals";allow (write) userattr = "managedby#GROUPDN" or userattr = "managedby#USERDN";) 2025-05-07T18:06:40Z DEBUG (targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Delegated permission to manage resource-based constrained delegation for other principals";allow (write) userattr="ipaAllowedToPerform;write_delegation#GROUPDN" or userattr="ipaAllowedToPerform;write_delegation#USERDN" ;) 2025-05-07T18:06:40Z DEBUG [(0, 'aci', ['(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Kerberos principals can manage resource-based constrained delegation for themselves";allow (write) userdn = "ldap:///self";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Managing principals can manage resource-based constrained delegation for other principals";allow (write) userattr = "managedby#GROUPDN" or userattr = "managedby#USERDN";)', '(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Delegated permission to manage resource-based constrained delegation for other principals";allow (write) userattr="ipaAllowedToPerform;write_delegation#GROUPDN" or userattr="ipaAllowedToPerform;write_delegation#USERDN" ;)'])] 2025-05-07T18:06:40Z DEBUG Updated 1 2025-05-07T18:06:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Kerberos principals can manage resource-based constrained delegation for themselves";allow (write) userdn = "ldap:///self";)', b'(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Managing principals can manage resource-based constrained delegation for other principals";allow (write) userattr = "managedby#GROUPDN" or userattr = "managedby#USERDN";)', b'(targetattr = "memberPrincipal")(targattrfilters="add=objectclass:(objectclass=resourcedelegation)")(version 3.0;acl "permission:RBCD:Delegated permission to manage resource-based constrained delegation for other principals";allow (write) userattr="ipaAllowedToPerform;write_delegation#GROUPDN" or userattr="ipaAllowedToPerform;write_delegation#USERDN" ;)'])] 2025-05-07T18:06:40Z DEBUG Done 2025-05-07T18:06:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-service-rbcd.update 0.020 sec 2025-05-07T18:06:40Z DEBUG Parsing update file '/usr/share/ipa/updates/73-subid.update' 2025-05-07T18:06:40Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG MemberOf Plugin 2025-05-07T18:06:40Z DEBUG memberofattr: 2025-05-07T18:06:40Z DEBUG memberOf 2025-05-07T18:06:40Z DEBUG memberofgroupattr: 2025-05-07T18:06:40Z DEBUG member 2025-05-07T18:06:40Z DEBUG memberUser 2025-05-07T18:06:40Z DEBUG memberHost 2025-05-07T18:06:40Z DEBUG ipaOwner 2025-05-07T18:06:40Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:40Z DEBUG database 2025-05-07T18:06:40Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:40Z DEBUG memberof plugin 2025-05-07T18:06:40Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:40Z DEBUG on 2025-05-07T18:06:40Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:40Z DEBUG memberof 2025-05-07T18:06:40Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:40Z DEBUG memberof_postop_init 2025-05-07T18:06:40Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:40Z DEBUG libmemberof-plugin 2025-05-07T18:06:40Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:40Z DEBUG betxnpostoperation 2025-05-07T18:06:40Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:40Z DEBUG 389 Project 2025-05-07T18:06:40Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:40Z DEBUG 3.1.2 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsSlapdPlugin 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG memberofentryscope: 2025-05-07T18:06:40Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG memberofentryscopeexcludesubtree: 2025-05-07T18:06:40Z DEBUG cn=compat,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG add: 'ipaOwner' to memberofgroupattr, current value ['member', 'memberUser', 'memberHost', 'ipaOwner'] 2025-05-07T18:06:40Z DEBUG add: updated value ['member', 'memberUser', 'memberHost', 'ipaOwner'] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG MemberOf Plugin 2025-05-07T18:06:40Z DEBUG memberofattr: 2025-05-07T18:06:40Z DEBUG memberOf 2025-05-07T18:06:40Z DEBUG memberofgroupattr: 2025-05-07T18:06:40Z DEBUG member 2025-05-07T18:06:40Z DEBUG memberUser 2025-05-07T18:06:40Z DEBUG memberHost 2025-05-07T18:06:40Z DEBUG ipaOwner 2025-05-07T18:06:40Z DEBUG nsslapd-plugin-depends-on-type: 2025-05-07T18:06:40Z DEBUG database 2025-05-07T18:06:40Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:40Z DEBUG memberof plugin 2025-05-07T18:06:40Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:40Z DEBUG on 2025-05-07T18:06:40Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:40Z DEBUG memberof 2025-05-07T18:06:40Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:40Z DEBUG memberof_postop_init 2025-05-07T18:06:40Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:40Z DEBUG libmemberof-plugin 2025-05-07T18:06:40Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:40Z DEBUG betxnpostoperation 2025-05-07T18:06:40Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:40Z DEBUG 389 Project 2025-05-07T18:06:40Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:40Z DEBUG 3.1.2 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsSlapdPlugin 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG memberofentryscope: 2025-05-07T18:06:40Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG memberofentryscopeexcludesubtree: 2025-05-07T18:06:40Z DEBUG cn=compat,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG [] 2025-05-07T18:06:40Z DEBUG Updated 0 2025-05-07T18:06:40Z DEBUG Done 2025-05-07T18:06:40Z DEBUG New entry: cn=subids,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=subids,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG subids 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=subids,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG subids 2025-05-07T18:06:40Z DEBUG New entry: cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Subordinate ID Selfservice User 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG User that can self-request subordinate ids 2025-05-07T18:06:40Z DEBUG replace: User that can self-request subordiante ids not found, skipping 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Subordinate ID Selfservice User 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG User that can self-request subordinate ids 2025-05-07T18:06:40Z DEBUG New entry: cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Subordinate ID Selfservice Users 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG Subordinate ID Selfservice User 2025-05-07T18:06:40Z DEBUG member: 2025-05-07T18:06:40Z DEBUG cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Subordinate ID Selfservice Users 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG Subordinate ID Selfservice User 2025-05-07T18:06:40Z DEBUG member: 2025-05-07T18:06:40Z DEBUG cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG New entry: cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG ipapermission 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Self-service subordinate ID 2025-05-07T18:06:40Z DEBUG ipapermissiontype: 2025-05-07T18:06:40Z DEBUG SYSTEM 2025-05-07T18:06:40Z DEBUG member: 2025-05-07T18:06:40Z DEBUG cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG ipapermission 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Self-service subordinate ID 2025-05-07T18:06:40Z DEBUG ipapermissiontype: 2025-05-07T18:06:40Z DEBUG SYSTEM 2025-05-07T18:06:40Z DEBUG member: 2025-05-07T18:06:40Z DEBUG cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG New entry: cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Subordinate ID Administrators 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG Subordinate ID Administrators 2025-05-07T18:06:40Z DEBUG member: 2025-05-07T18:06:40Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG nestedgroup 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Subordinate ID Administrators 2025-05-07T18:06:40Z DEBUG description: 2025-05-07T18:06:40Z DEBUG Subordinate ID Administrators 2025-05-07T18:06:40Z DEBUG member: 2025-05-07T18:06:40Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG New entry: cn=Manage subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=Manage subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG ipapermission 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Manage subordinate ID 2025-05-07T18:06:40Z DEBUG ipapermissiontype: 2025-05-07T18:06:40Z DEBUG SYSTEM 2025-05-07T18:06:40Z DEBUG member: 2025-05-07T18:06:40Z DEBUG cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=Manage subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG groupofnames 2025-05-07T18:06:40Z DEBUG ipapermission 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Manage subordinate ID 2025-05-07T18:06:40Z DEBUG ipapermissiontype: 2025-05-07T18:06:40Z DEBUG SYSTEM 2025-05-07T18:06:40Z DEBUG member: 2025-05-07T18:06:40Z DEBUG cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG Updating existing entry: cn=subids,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=subids,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG subids 2025-05-07T18:06:40Z DEBUG add: '(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:40Z DEBUG add: '(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:40Z DEBUG add: updated value ['(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=subids,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG subids 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG [(2, 'aci', ['(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:40Z DEBUG Updated 1 2025-05-07T18:06:40Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', b'(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:06:40Z DEBUG Done 2025-05-07T18:06:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-subid.update 0.296 sec 2025-05-07T18:06:40Z DEBUG Parsing update file '/usr/share/ipa/updates/73-winsync.update' 2025-05-07T18:06:40Z DEBUG New entry: uid=passsync,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG addifexist: 'inetUser' to objectClass, current value [] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-winsync.update 0.011 sec 2025-05-07T18:06:40Z DEBUG Parsing update file '/usr/share/ipa/updates/75-user-trust-attributes.update' 2025-05-07T18:06:40Z DEBUG Updating existing entry: cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG users 2025-05-07T18:06:40Z DEBUG add: '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)' to aci, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:40Z DEBUG add: '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)'] 2025-05-07T18:06:40Z DEBUG add: updated value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)'] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=users,cn=accounts,dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsContainer 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG users 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";) 2025-05-07T18:06:40Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";) 2025-05-07T18:06:40Z DEBUG [(2, 'aci', ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)'])] 2025-05-07T18:06:40Z DEBUG Updated 1 2025-05-07T18:06:40Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test";)', b'(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)'])] 2025-05-07T18:06:40Z DEBUG Done 2025-05-07T18:06:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/75-user-trust-attributes.update 0.023 sec 2025-05-07T18:06:40Z DEBUG Parsing update file '/usr/share/ipa/updates/80-schema_compat.update' 2025-05-07T18:06:40Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectclass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsSlapdPlugin 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Schema Compatibility 2025-05-07T18:06:40Z DEBUG nsslapd-pluginpath: 2025-05-07T18:06:40Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2025-05-07T18:06:40Z DEBUG nsslapd-plugininitfunc: 2025-05-07T18:06:40Z DEBUG schema_compat_plugin_init 2025-05-07T18:06:40Z DEBUG nsslapd-plugintype: 2025-05-07T18:06:40Z DEBUG object 2025-05-07T18:06:40Z DEBUG nsslapd-pluginenabled: 2025-05-07T18:06:40Z DEBUG on 2025-05-07T18:06:40Z DEBUG nsslapd-pluginid: 2025-05-07T18:06:40Z DEBUG schema-compat-plugin 2025-05-07T18:06:40Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:40Z DEBUG 40 2025-05-07T18:06:40Z DEBUG nsslapd-pluginversion: 2025-05-07T18:06:40Z DEBUG 0.8 2025-05-07T18:06:40Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:40Z DEBUG on 2025-05-07T18:06:40Z DEBUG nsslapd-pluginvendor: 2025-05-07T18:06:40Z DEBUG redhat.com 2025-05-07T18:06:40Z DEBUG nsslapd-plugindescription: 2025-05-07T18:06:40Z DEBUG Schema Compatibility Plugin 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectclass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG nsSlapdPlugin 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG Schema Compatibility 2025-05-07T18:06:40Z DEBUG nsslapd-pluginpath: 2025-05-07T18:06:40Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2025-05-07T18:06:40Z DEBUG nsslapd-plugininitfunc: 2025-05-07T18:06:40Z DEBUG schema_compat_plugin_init 2025-05-07T18:06:40Z DEBUG nsslapd-plugintype: 2025-05-07T18:06:40Z DEBUG object 2025-05-07T18:06:40Z DEBUG nsslapd-pluginenabled: 2025-05-07T18:06:40Z DEBUG on 2025-05-07T18:06:40Z DEBUG nsslapd-pluginid: 2025-05-07T18:06:40Z DEBUG schema-compat-plugin 2025-05-07T18:06:40Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:40Z DEBUG 40 2025-05-07T18:06:40Z DEBUG nsslapd-pluginversion: 2025-05-07T18:06:40Z DEBUG 0.8 2025-05-07T18:06:40Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:40Z DEBUG on 2025-05-07T18:06:40Z DEBUG nsslapd-pluginvendor: 2025-05-07T18:06:40Z DEBUG redhat.com 2025-05-07T18:06:40Z DEBUG nsslapd-plugindescription: 2025-05-07T18:06:40Z DEBUG Schema Compatibility Plugin 2025-05-07T18:06:40Z DEBUG New entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG users 2025-05-07T18:06:40Z DEBUG schema-compat-container-group: 2025-05-07T18:06:40Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:40Z DEBUG cn=users 2025-05-07T18:06:40Z DEBUG schema-compat-search-base: 2025-05-07T18:06:40Z DEBUG cn=users, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:40Z DEBUG objectclass=posixAccount 2025-05-07T18:06:40Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:40Z DEBUG uid=%{uid} 2025-05-07T18:06:40Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:40Z DEBUG objectclass=posixAccount 2025-05-07T18:06:40Z DEBUG gecos=%{cn} 2025-05-07T18:06:40Z DEBUG cn=%{cn} 2025-05-07T18:06:40Z DEBUG uidNumber=%{uidNumber} 2025-05-07T18:06:40Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:40Z DEBUG loginShell=%{loginShell} 2025-05-07T18:06:40Z DEBUG homeDirectory=%{homeDirectory} 2025-05-07T18:06:40Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:40Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:40Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:40Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG users 2025-05-07T18:06:40Z DEBUG schema-compat-container-group: 2025-05-07T18:06:40Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:40Z DEBUG cn=users 2025-05-07T18:06:40Z DEBUG schema-compat-search-base: 2025-05-07T18:06:40Z DEBUG cn=users, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:40Z DEBUG objectclass=posixAccount 2025-05-07T18:06:40Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:40Z DEBUG uid=%{uid} 2025-05-07T18:06:40Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:40Z DEBUG objectclass=posixAccount 2025-05-07T18:06:40Z DEBUG gecos=%{cn} 2025-05-07T18:06:40Z DEBUG cn=%{cn} 2025-05-07T18:06:40Z DEBUG uidNumber=%{uidNumber} 2025-05-07T18:06:40Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:40Z DEBUG loginShell=%{loginShell} 2025-05-07T18:06:40Z DEBUG homeDirectory=%{homeDirectory} 2025-05-07T18:06:40Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:40Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:40Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:40Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:40Z DEBUG New entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG groups 2025-05-07T18:06:40Z DEBUG schema-compat-container-group: 2025-05-07T18:06:40Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:40Z DEBUG cn=groups 2025-05-07T18:06:40Z DEBUG schema-compat-search-base: 2025-05-07T18:06:40Z DEBUG cn=groups, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:40Z DEBUG objectclass=posixGroup 2025-05-07T18:06:40Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:40Z DEBUG cn=%{cn} 2025-05-07T18:06:40Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:40Z DEBUG objectclass=posixGroup 2025-05-07T18:06:40Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:40Z DEBUG memberUid=%{memberUid} 2025-05-07T18:06:40Z DEBUG memberUid=%deref_r("member","uid") 2025-05-07T18:06:40Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:40Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:40Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:40Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG groups 2025-05-07T18:06:40Z DEBUG schema-compat-container-group: 2025-05-07T18:06:40Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:40Z DEBUG cn=groups 2025-05-07T18:06:40Z DEBUG schema-compat-search-base: 2025-05-07T18:06:40Z DEBUG cn=groups, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:40Z DEBUG objectclass=posixGroup 2025-05-07T18:06:40Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:40Z DEBUG cn=%{cn} 2025-05-07T18:06:40Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:40Z DEBUG objectclass=posixGroup 2025-05-07T18:06:40Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:40Z DEBUG memberUid=%{memberUid} 2025-05-07T18:06:40Z DEBUG memberUid=%deref_r("member","uid") 2025-05-07T18:06:40Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:40Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:40Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:40Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:40Z DEBUG New entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG add: 'top' to objectClass, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['top'] 2025-05-07T18:06:40Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2025-05-07T18:06:40Z DEBUG add: updated value ['top', 'extensibleObject'] 2025-05-07T18:06:40Z DEBUG add: 'ng' to cn, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['ng'] 2025-05-07T18:06:40Z DEBUG add: 'cn=compat, dc=ufreeipa,dc=test' to schema-compat-container-group, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['cn=compat, dc=ufreeipa,dc=test'] 2025-05-07T18:06:40Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['cn=ng'] 2025-05-07T18:06:40Z DEBUG add: 'yes' to schema-compat-check-access, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['yes'] 2025-05-07T18:06:40Z DEBUG add: 'cn=ng, cn=alt, dc=ufreeipa,dc=test' to schema-compat-search-base, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['cn=ng, cn=alt, dc=ufreeipa,dc=test'] 2025-05-07T18:06:40Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['(objectclass=ipaNisNetgroup)'] 2025-05-07T18:06:40Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['cn=%{cn}'] 2025-05-07T18:06:40Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=nisNetgroup'] 2025-05-07T18:06:40Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")'] 2025-05-07T18:06:40Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG ng 2025-05-07T18:06:40Z DEBUG schema-compat-container-group: 2025-05-07T18:06:40Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:40Z DEBUG cn=ng 2025-05-07T18:06:40Z DEBUG schema-compat-check-access: 2025-05-07T18:06:40Z DEBUG yes 2025-05-07T18:06:40Z DEBUG schema-compat-search-base: 2025-05-07T18:06:40Z DEBUG cn=ng, cn=alt, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:40Z DEBUG (objectclass=ipaNisNetgroup) 2025-05-07T18:06:40Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:40Z DEBUG cn=%{cn} 2025-05-07T18:06:40Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:40Z DEBUG objectclass=nisNetgroup 2025-05-07T18:06:40Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2025-05-07T18:06:40Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2025-05-07T18:06:40Z DEBUG New entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG add: 'top' to objectClass, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['top'] 2025-05-07T18:06:40Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2025-05-07T18:06:40Z DEBUG add: updated value ['top', 'extensibleObject'] 2025-05-07T18:06:40Z DEBUG add: 'sudoers' to cn, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['sudoers'] 2025-05-07T18:06:40Z DEBUG add: 'ou=SUDOers, dc=ufreeipa,dc=test' to schema-compat-container-group, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['ou=SUDOers, dc=ufreeipa,dc=test'] 2025-05-07T18:06:40Z DEBUG add: 'cn=sudorules, cn=sudo, dc=ufreeipa,dc=test' to schema-compat-search-base, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['cn=sudorules, cn=sudo, dc=ufreeipa,dc=test'] 2025-05-07T18:06:40Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] 2025-05-07T18:06:40Z DEBUG add: '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")' to schema-compat-entry-rdn, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2025-05-07T18:06:40Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value [] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole'] 2025-05-07T18:06:40Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2025-05-07T18:06:40Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG sudoers 2025-05-07T18:06:40Z DEBUG schema-compat-container-group: 2025-05-07T18:06:40Z DEBUG ou=SUDOers, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-search-base: 2025-05-07T18:06:40Z DEBUG cn=sudorules, cn=sudo, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:40Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2025-05-07T18:06:40Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:40Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2025-05-07T18:06:40Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:40Z DEBUG objectclass=sudoRole 2025-05-07T18:06:40Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2025-05-07T18:06:40Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:40Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2025-05-07T18:06:40Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:40Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:40Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2025-05-07T18:06:40Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2025-05-07T18:06:40Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2025-05-07T18:06:40Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2025-05-07T18:06:40Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:40Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2025-05-07T18:06:40Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2025-05-07T18:06:40Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2025-05-07T18:06:40Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2025-05-07T18:06:40Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2025-05-07T18:06:40Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2025-05-07T18:06:40Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2025-05-07T18:06:40Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:40Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:40Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2025-05-07T18:06:40Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:40Z DEBUG sudoOption=%{ipaSudoOpt} 2025-05-07T18:06:40Z DEBUG New entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG computers 2025-05-07T18:06:40Z DEBUG schema-compat-container-group: 2025-05-07T18:06:40Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:40Z DEBUG cn=computers 2025-05-07T18:06:40Z DEBUG schema-compat-search-base: 2025-05-07T18:06:40Z DEBUG cn=computers, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:40Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2025-05-07T18:06:40Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:40Z DEBUG cn=%first("%{fqdn}") 2025-05-07T18:06:40Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:40Z DEBUG objectclass=device 2025-05-07T18:06:40Z DEBUG objectclass=ieee802Device 2025-05-07T18:06:40Z DEBUG cn=%{fqdn} 2025-05-07T18:06:40Z DEBUG macAddress=%{macAddress} 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG extensibleObject 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG computers 2025-05-07T18:06:40Z DEBUG schema-compat-container-group: 2025-05-07T18:06:40Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:40Z DEBUG cn=computers 2025-05-07T18:06:40Z DEBUG schema-compat-search-base: 2025-05-07T18:06:40Z DEBUG cn=computers, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:40Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:40Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2025-05-07T18:06:40Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:40Z DEBUG cn=%first("%{fqdn}") 2025-05-07T18:06:40Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:40Z DEBUG objectclass=device 2025-05-07T18:06:40Z DEBUG objectclass=ieee802Device 2025-05-07T18:06:40Z DEBUG cn=%{fqdn} 2025-05-07T18:06:40Z DEBUG macAddress=%{macAddress} 2025-05-07T18:06:40Z DEBUG Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Initial value 2025-05-07T18:06:40Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG VLV Request Control 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG directoryServerFeature 2025-05-07T18:06:40Z DEBUG oid: 2025-05-07T18:06:40Z DEBUG 2.16.840.1.113730.3.4.9 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";) 2025-05-07T18:06:40Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'] 2025-05-07T18:06:40Z DEBUG only: updated value ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] 2025-05-07T18:06:40Z DEBUG --------------------------------------------- 2025-05-07T18:06:40Z DEBUG Final value after applying updates 2025-05-07T18:06:40Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2025-05-07T18:06:40Z DEBUG cn: 2025-05-07T18:06:40Z DEBUG VLV Request Control 2025-05-07T18:06:40Z DEBUG objectClass: 2025-05-07T18:06:40Z DEBUG top 2025-05-07T18:06:40Z DEBUG directoryServerFeature 2025-05-07T18:06:40Z DEBUG oid: 2025-05-07T18:06:40Z DEBUG 2.16.840.1.113730.3.4.9 2025-05-07T18:06:40Z DEBUG aci: 2025-05-07T18:06:40Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) 2025-05-07T18:06:40Z DEBUG [(1, 'aci', ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)']), (0, 'aci', ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'])] 2025-05-07T18:06:40Z DEBUG Updated 1 2025-05-07T18:06:40Z DEBUG update_entry modlist [(1, 'aci', [b'(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)']), (0, 'aci', [b'(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'])] 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG sudoers 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG ou=SUDOers, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=sudorules, cn=sudo, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=sudoRole 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoOption=%{ipaSudoOpt} 2025-05-07T18:06:41Z DEBUG only: set schema-compat-entry-rdn to '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")', current value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2025-05-07T18:06:41Z DEBUG only: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2025-05-07T18:06:41Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2025-05-07T18:06:41Z DEBUG add: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' not in schema-compat-entry-attribute 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' not in schema-compat-entry-attribute 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2025-05-07T18:06:41Z DEBUG remove: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' not in schema-compat-entry-attribute 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' not in schema-compat-entry-attribute 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2025-05-07T18:06:41Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' not in schema-compat-entry-attribute 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG sudoers 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG ou=SUDOers, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=sudorules, cn=sudo, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=sudoRole 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoOption=%{ipaSudoOpt} 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2025-05-07T18:06:41Z DEBUG [] 2025-05-07T18:06:41Z DEBUG Updated 0 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG sudoers 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG ou=SUDOers, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=sudorules, cn=sudo, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=sudoRole 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoOption=%{ipaSudoOpt} 2025-05-07T18:06:41Z DEBUG add: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2025-05-07T18:06:41Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2025-05-07T18:06:41Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2025-05-07T18:06:41Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2025-05-07T18:06:41Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2025-05-07T18:06:41Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG add: 'dc=ufreeipa,dc=test' to schema-compat-restrict-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2025-05-07T18:06:41Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG sudoers 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG ou=SUDOers, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=sudorules, cn=sudo, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=sudoRole 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoOption=%{ipaSudoOpt} 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG [(0, 'schema-compat-entry-attribute', ['sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")']), (2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Updated 1 2025-05-07T18:06:41Z DEBUG update_entry modlist [(0, 'schema-compat-entry-attribute', [b'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")']), (2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', b'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', [b'dc=ufreeipa,dc=test', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG ng 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=ng 2025-05-07T18:06:41Z DEBUG schema-compat-check-access: 2025-05-07T18:06:41Z DEBUG yes 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=ng, cn=alt, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (objectclass=ipaNisNetgroup) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=nisNetgroup 2025-05-07T18:06:41Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2025-05-07T18:06:41Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2025-05-07T18:06:41Z DEBUG replace: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})'] 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG add: 'dc=ufreeipa,dc=test' to schema-compat-restrict-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2025-05-07T18:06:41Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG ng 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=ng 2025-05-07T18:06:41Z DEBUG schema-compat-check-access: 2025-05-07T18:06:41Z DEBUG yes 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=ng, cn=alt, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (objectclass=ipaNisNetgroup) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=nisNetgroup 2025-05-07T18:06:41Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2025-05-07T18:06:41Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG [(1, 'schema-compat-entry-attribute', ['nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})']), (0, 'schema-compat-entry-attribute', ['nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})']), (2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Updated 1 2025-05-07T18:06:41Z DEBUG update_entry modlist [(1, 'schema-compat-entry-attribute', [b'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})']), (0, 'schema-compat-entry-attribute', [b'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})']), (2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', b'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', [b'dc=ufreeipa,dc=test', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG computers 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=computers 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=computers, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%first("%{fqdn}") 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=device 2025-05-07T18:06:41Z DEBUG objectclass=ieee802Device 2025-05-07T18:06:41Z DEBUG cn=%{fqdn} 2025-05-07T18:06:41Z DEBUG macAddress=%{macAddress} 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG add: 'dc=ufreeipa,dc=test' to schema-compat-restrict-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2025-05-07T18:06:41Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG computers 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=computers 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=computers, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%first("%{fqdn}") 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=device 2025-05-07T18:06:41Z DEBUG objectclass=ieee802Device 2025-05-07T18:06:41Z DEBUG cn=%{fqdn} 2025-05-07T18:06:41Z DEBUG macAddress=%{macAddress} 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Updated 1 2025-05-07T18:06:41Z DEBUG update_entry modlist [(2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', b'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', [b'dc=ufreeipa,dc=test', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG sudoers 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG ou=SUDOers, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=sudorules, cn=sudo, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=sudoRole 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoOption=%{ipaSudoOpt} 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG add: 'sudoOrder=%{sudoOrder}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoOrder=%{sudoOrder}'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG sudoers 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG ou=SUDOers, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=sudorules, cn=sudo, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=sudoRole 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2025-05-07T18:06:41Z DEBUG sudoOption=%{ipaSudoOpt} 2025-05-07T18:06:41Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2025-05-07T18:06:41Z DEBUG sudoOrder=%{sudoOrder} 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG [(0, 'schema-compat-entry-attribute', ['sudoOrder=%{sudoOrder}'])] 2025-05-07T18:06:41Z DEBUG Updated 1 2025-05-07T18:06:41Z DEBUG update_entry modlist [(0, 'schema-compat-entry-attribute', [b'sudoOrder=%{sudoOrder}'])] 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG users 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=users 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=users, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG uid=%{uid} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG gecos=%{cn} 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG uidNumber=%{uidNumber} 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG loginShell=%{loginShell} 2025-05-07T18:06:41Z DEBUG homeDirectory=%{homeDirectory} 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG add: 'dc=ufreeipa,dc=test' to schema-compat-restrict-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2025-05-07T18:06:41Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG users 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=users 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=users, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG uid=%{uid} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG gecos=%{cn} 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG uidNumber=%{uidNumber} 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG loginShell=%{loginShell} 2025-05-07T18:06:41Z DEBUG homeDirectory=%{homeDirectory} 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Updated 1 2025-05-07T18:06:41Z DEBUG update_entry modlist [(2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', b'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', [b'dc=ufreeipa,dc=test', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG groups 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=groups 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=groups, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG memberUid=%{memberUid} 2025-05-07T18:06:41Z DEBUG memberUid=%deref_r("member","uid") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2025-05-07T18:06:41Z DEBUG add: 'dc=ufreeipa,dc=test' to schema-compat-restrict-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2025-05-07T18:06:41Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value [] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG groups 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=groups 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=groups, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG memberUid=%{memberUid} 2025-05-07T18:06:41Z DEBUG memberUid=%deref_r("member","uid") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', ['dc=ufreeipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Updated 1 2025-05-07T18:06:41Z DEBUG update_entry modlist [(2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test', b'cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test']), (2, 'schema-compat-restrict-subtree', [b'dc=ufreeipa,dc=test', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG nsSlapdPlugin 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG Schema Compatibility 2025-05-07T18:06:41Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:41Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2025-05-07T18:06:41Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:41Z DEBUG schema_compat_plugin_init 2025-05-07T18:06:41Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:41Z DEBUG object 2025-05-07T18:06:41Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:41Z DEBUG on 2025-05-07T18:06:41Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:41Z DEBUG schema-compat-plugin 2025-05-07T18:06:41Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:41Z DEBUG 40 2025-05-07T18:06:41Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:41Z DEBUG 0.8 2025-05-07T18:06:41Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:41Z DEBUG on 2025-05-07T18:06:41Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:41Z DEBUG redhat.com 2025-05-07T18:06:41Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:41Z DEBUG Schema Compatibility Plugin 2025-05-07T18:06:41Z DEBUG add: '40' to nsslapd-pluginprecedence, current value ['40'] 2025-05-07T18:06:41Z DEBUG add: updated value ['40'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG nsSlapdPlugin 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG Schema Compatibility 2025-05-07T18:06:41Z DEBUG nsslapd-pluginPath: 2025-05-07T18:06:41Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2025-05-07T18:06:41Z DEBUG nsslapd-pluginInitfunc: 2025-05-07T18:06:41Z DEBUG schema_compat_plugin_init 2025-05-07T18:06:41Z DEBUG nsslapd-pluginType: 2025-05-07T18:06:41Z DEBUG object 2025-05-07T18:06:41Z DEBUG nsslapd-pluginEnabled: 2025-05-07T18:06:41Z DEBUG on 2025-05-07T18:06:41Z DEBUG nsslapd-pluginId: 2025-05-07T18:06:41Z DEBUG schema-compat-plugin 2025-05-07T18:06:41Z DEBUG nsslapd-pluginprecedence: 2025-05-07T18:06:41Z DEBUG 40 2025-05-07T18:06:41Z DEBUG nsslapd-pluginVersion: 2025-05-07T18:06:41Z DEBUG 0.8 2025-05-07T18:06:41Z DEBUG nsslapd-pluginbetxn: 2025-05-07T18:06:41Z DEBUG on 2025-05-07T18:06:41Z DEBUG nsslapd-pluginVendor: 2025-05-07T18:06:41Z DEBUG redhat.com 2025-05-07T18:06:41Z DEBUG nsslapd-pluginDescription: 2025-05-07T18:06:41Z DEBUG Schema Compatibility Plugin 2025-05-07T18:06:41Z DEBUG [] 2025-05-07T18:06:41Z DEBUG Updated 0 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG users 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=users 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=users, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG uid=%{uid} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG gecos=%{cn} 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG uidNumber=%{uidNumber} 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG loginShell=%{loginShell} 2025-05-07T18:06:41Z DEBUG homeDirectory=%{homeDirectory} 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")'] 2025-05-07T18:06:41Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2025-05-07T18:06:41Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG users 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=users 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=users, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG uid=%{uid} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG gecos=%{cn} 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG uidNumber=%{uidNumber} 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG loginShell=%{loginShell} 2025-05-07T18:06:41Z DEBUG homeDirectory=%{homeDirectory} 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG [] 2025-05-07T18:06:41Z DEBUG Updated 0 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG groups 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=groups 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=groups, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG memberUid=%{memberUid} 2025-05-07T18:06:41Z DEBUG memberUid=%deref_r("member","uid") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")'] 2025-05-07T18:06:41Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2025-05-07T18:06:41Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG groups 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=groups 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=groups, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG memberUid=%{memberUid} 2025-05-07T18:06:41Z DEBUG memberUid=%deref_r("member","uid") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG [] 2025-05-07T18:06:41Z DEBUG Updated 0 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG users 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=users 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=users, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG uid=%{uid} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG gecos=%{cn} 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG uidNumber=%{uidNumber} 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG loginShell=%{loginShell} 2025-05-07T18:06:41Z DEBUG homeDirectory=%{homeDirectory} 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG add: 'uid=%{uid}' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'uid=%{uid}'] 2025-05-07T18:06:41Z DEBUG replace: updated value ['uid=%first("%{uid}")'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG users 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=users 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=users, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG uid=%first("%{uid}") 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixAccount 2025-05-07T18:06:41Z DEBUG gecos=%{cn} 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG uidNumber=%{uidNumber} 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG loginShell=%{loginShell} 2025-05-07T18:06:41Z DEBUG homeDirectory=%{homeDirectory} 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG uid=%{uid} 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG [(0, 'schema-compat-entry-attribute', ['uid=%{uid}']), (1, 'schema-compat-entry-rdn', ['uid=%{uid}']), (0, 'schema-compat-entry-rdn', ['uid=%first("%{uid}")'])] 2025-05-07T18:06:41Z DEBUG Updated 1 2025-05-07T18:06:41Z DEBUG update_entry modlist [(0, 'schema-compat-entry-attribute', [b'uid=%{uid}']), (1, 'schema-compat-entry-rdn', [b'uid=%{uid}']), (0, 'schema-compat-entry-rdn', [b'uid=%first("%{uid}")'])] 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/80-schema_compat.update 0.560 sec 2025-05-07T18:06:41Z DEBUG Parsing update file '/usr/share/ipa/updates/81-externalmembers.update' 2025-05-07T18:06:41Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Initial value 2025-05-07T18:06:41Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG groups 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=groups 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=groups, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG memberUid=%{memberUid} 2025-05-07T18:06:41Z DEBUG memberUid=%deref_r("member","uid") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG addifexist: 'ipaexternalmember=%deref_r("member","ipaexternalmember")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2025-05-07T18:06:41Z DEBUG addifexist: set schema-compat-entry-attribute to ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2025-05-07T18:06:41Z DEBUG addifexist: 'objectclass=ipaexternalgroup' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2025-05-07T18:06:41Z DEBUG addifexist: set schema-compat-entry-attribute to ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")', 'objectclass=ipaexternalgroup'] 2025-05-07T18:06:41Z DEBUG --------------------------------------------- 2025-05-07T18:06:41Z DEBUG Final value after applying updates 2025-05-07T18:06:41Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG objectClass: 2025-05-07T18:06:41Z DEBUG top 2025-05-07T18:06:41Z DEBUG extensibleObject 2025-05-07T18:06:41Z DEBUG cn: 2025-05-07T18:06:41Z DEBUG groups 2025-05-07T18:06:41Z DEBUG schema-compat-container-group: 2025-05-07T18:06:41Z DEBUG cn=compat, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-container-rdn: 2025-05-07T18:06:41Z DEBUG cn=groups 2025-05-07T18:06:41Z DEBUG schema-compat-search-base: 2025-05-07T18:06:41Z DEBUG cn=groups, cn=accounts, dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-search-filter: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG schema-compat-entry-rdn: 2025-05-07T18:06:41Z DEBUG cn=%{cn} 2025-05-07T18:06:41Z DEBUG schema-compat-entry-attribute: 2025-05-07T18:06:41Z DEBUG objectclass=posixGroup 2025-05-07T18:06:41Z DEBUG gidNumber=%{gidNumber} 2025-05-07T18:06:41Z DEBUG memberUid=%{memberUid} 2025-05-07T18:06:41Z DEBUG memberUid=%deref_r("member","uid") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ufreeipa.test:%{ipauniqueid}","") 2025-05-07T18:06:41Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2025-05-07T18:06:41Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2025-05-07T18:06:41Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2025-05-07T18:06:41Z DEBUG objectclass=ipaexternalgroup 2025-05-07T18:06:41Z DEBUG schema-compat-ignore-subtree: 2025-05-07T18:06:41Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG schema-compat-restrict-subtree: 2025-05-07T18:06:41Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:41Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2025-05-07T18:06:41Z DEBUG [(0, 'schema-compat-entry-attribute', ['ipaexternalmember=%deref_r("member","ipaexternalmember")', 'objectclass=ipaexternalgroup'])] 2025-05-07T18:06:41Z DEBUG Updated 1 2025-05-07T18:06:41Z DEBUG update_entry modlist [(0, 'schema-compat-entry-attribute', [b'ipaexternalmember=%deref_r("member","ipaexternalmember")', b'objectclass=ipaexternalgroup'])] 2025-05-07T18:06:41Z DEBUG Done 2025-05-07T18:06:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/81-externalmembers.update 0.058 sec 2025-05-07T18:06:41Z DEBUG Parsing update file '/usr/share/ipa/updates/90-post_upgrade_plugins.update' 2025-05-07T18:06:41Z DEBUG Executing upgrade plugin: update_ca_topology 2025-05-07T18:06:41Z DEBUG raw: update_ca_topology 2025-05-07T18:06:41Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:41Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:06:41Z DEBUG importing all plugin modules in ipaserver.plugins... 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.aci 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.automember 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.automount 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.baseldap 2025-05-07T18:06:41Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.baseuser 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.batch 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.ca 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.caacl 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.cert 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.certmap 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.certprofile 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.config 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.delegation 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.dns 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.dogtag 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.group 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.hbac 2025-05-07T18:06:41Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.hbactest 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.host 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.idp 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.idrange 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.idviews 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.internal 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.join 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.ldap2 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.location 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.migration 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.misc 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.netgroup 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.otp 2025-05-07T18:06:41Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.otptoken 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.passkeyconfig 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.passwd 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.permission 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.ping 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.pkinit 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.privilege 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.rabase 2025-05-07T18:06:41Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.role 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.schema 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.selfservice 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.server 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.serverrole 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.serverroles 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.service 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.session 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.stageuser 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.subid 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.sudo 2025-05-07T18:06:41Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.sudorule 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.topology 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.trust 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.user 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.vault 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.virtual 2025-05-07T18:06:41Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.whoami 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2025-05-07T18:06:41Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.dns 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_subid_support 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2025-05-07T18:06:41Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2025-05-07T18:06:41Z DEBUG Created connection context.ldap2_139937119827584 2025-05-07T18:06:41Z DEBUG raw: idrange_show('UFREEIPA.TEST_id_range', version='2.254') 2025-05-07T18:06:41Z DEBUG idrange_show('UFREEIPA.TEST_id_range', rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:06:42Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:06:42Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:06:42Z DEBUG Parsing update file '/usr/share/ipa/ca-topology.uldif' 2025-05-07T18:06:42Z DEBUG Updating existing entry: cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:42Z DEBUG --------------------------------------------- 2025-05-07T18:06:42Z DEBUG Initial value 2025-05-07T18:06:42Z DEBUG dn: cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:42Z DEBUG objectClass: 2025-05-07T18:06:42Z DEBUG top 2025-05-07T18:06:42Z DEBUG nsContainer 2025-05-07T18:06:42Z DEBUG ipaReplTopoManagedServer 2025-05-07T18:06:42Z DEBUG ipaConfigObject 2025-05-07T18:06:42Z DEBUG ipaSupportedDomainLevelConfig 2025-05-07T18:06:42Z DEBUG cn: 2025-05-07T18:06:42Z DEBUG master.ufreeipa.test 2025-05-07T18:06:42Z DEBUG ipaReplTopoManagedSuffix: 2025-05-07T18:06:42Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:42Z DEBUG ipaMinDomainLevel: 2025-05-07T18:06:42Z DEBUG 1 2025-05-07T18:06:42Z DEBUG ipaMaxDomainLevel: 2025-05-07T18:06:42Z DEBUG 1 2025-05-07T18:06:42Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2025-05-07T18:06:42Z DEBUG add: updated value ['top', 'nsContainer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig', 'ipaReplTopoManagedServer'] 2025-05-07T18:06:42Z DEBUG add: 'o=ipaca' to ipaReplTopoManagedSuffix, current value ['dc=ufreeipa,dc=test'] 2025-05-07T18:06:42Z DEBUG add: updated value ['dc=ufreeipa,dc=test', 'o=ipaca'] 2025-05-07T18:06:42Z DEBUG --------------------------------------------- 2025-05-07T18:06:42Z DEBUG Final value after applying updates 2025-05-07T18:06:42Z DEBUG dn: cn=master.ufreeipa.test,cn=masters,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:42Z DEBUG objectClass: 2025-05-07T18:06:42Z DEBUG top 2025-05-07T18:06:42Z DEBUG nsContainer 2025-05-07T18:06:42Z DEBUG ipaConfigObject 2025-05-07T18:06:42Z DEBUG ipaSupportedDomainLevelConfig 2025-05-07T18:06:42Z DEBUG ipaReplTopoManagedServer 2025-05-07T18:06:42Z DEBUG cn: 2025-05-07T18:06:42Z DEBUG master.ufreeipa.test 2025-05-07T18:06:42Z DEBUG ipaReplTopoManagedSuffix: 2025-05-07T18:06:42Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:06:42Z DEBUG o=ipaca 2025-05-07T18:06:42Z DEBUG ipaMinDomainLevel: 2025-05-07T18:06:42Z DEBUG 1 2025-05-07T18:06:42Z DEBUG ipaMaxDomainLevel: 2025-05-07T18:06:42Z DEBUG 1 2025-05-07T18:06:42Z DEBUG [(0, 'ipaReplTopoManagedSuffix', ['o=ipaca'])] 2025-05-07T18:06:42Z DEBUG Updated 1 2025-05-07T18:06:42Z DEBUG update_entry modlist [(0, 'ipaReplTopoManagedSuffix', [b'o=ipaca'])] 2025-05-07T18:06:42Z DEBUG Done 2025-05-07T18:06:42Z DEBUG New entry: cn=ca,cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:42Z DEBUG --------------------------------------------- 2025-05-07T18:06:42Z DEBUG Initial value 2025-05-07T18:06:42Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:42Z DEBUG objectclass: 2025-05-07T18:06:42Z DEBUG top 2025-05-07T18:06:42Z DEBUG iparepltopoconf 2025-05-07T18:06:42Z DEBUG ipaReplTopoConfRoot: 2025-05-07T18:06:42Z DEBUG o=ipaca 2025-05-07T18:06:42Z DEBUG cn: 2025-05-07T18:06:42Z DEBUG ca 2025-05-07T18:06:42Z DEBUG --------------------------------------------- 2025-05-07T18:06:42Z DEBUG Final value after applying updates 2025-05-07T18:06:42Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:06:42Z DEBUG objectclass: 2025-05-07T18:06:42Z DEBUG top 2025-05-07T18:06:42Z DEBUG iparepltopoconf 2025-05-07T18:06:42Z DEBUG ipaReplTopoConfRoot: 2025-05-07T18:06:42Z DEBUG o=ipaca 2025-05-07T18:06:42Z DEBUG cn: 2025-05-07T18:06:42Z DEBUG ca 2025-05-07T18:06:42Z DEBUG New entry: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2025-05-07T18:06:42Z DEBUG --------------------------------------------- 2025-05-07T18:06:42Z DEBUG Initial value 2025-05-07T18:06:42Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2025-05-07T18:06:42Z DEBUG onlyifexist: 'cn=replication managers,cn=sysaccounts,cn=etc,dc=ufreeipa,dc=test' to nsds5replicabinddngroup, current value [] 2025-05-07T18:06:42Z DEBUG --------------------------------------------- 2025-05-07T18:06:42Z DEBUG Final value after applying updates 2025-05-07T18:06:42Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2025-05-07T18:06:42Z DEBUG LDAP update duration: /usr/share/ipa/ca-topology.uldif 0.057 sec 2025-05-07T18:06:42Z DEBUG Destroyed connection context.ldap2_139937119827584 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_ipaconfigstring_dnsversion_to_ipadnsversion 2025-05-07T18:06:42Z DEBUG raw: update_ipaconfigstring_dnsversion_to_ipadnsversion 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_dnszones 2025-05-07T18:06:42Z DEBUG raw: update_dnszones 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_dns_limits 2025-05-07T18:06:42Z DEBUG raw: update_dns_limits 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_sigden_extdom_broken_config 2025-05-07T18:06:42Z DEBUG raw: update_sigden_extdom_broken_config 2025-05-07T18:06:42Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:42Z DEBUG configured basedn for cn=IPA SIDGEN,cn=plugins,cn=config is okay 2025-05-07T18:06:42Z DEBUG configured basedn for cn=ipa_extdom_extop,cn=plugins,cn=config is okay 2025-05-07T18:06:42Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:42Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_sids 2025-05-07T18:06:42Z DEBUG raw: update_sids 2025-05-07T18:06:42Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:06:42Z DEBUG SIDs do not need to be generated 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_default_range 2025-05-07T18:06:42Z DEBUG raw: update_default_range 2025-05-07T18:06:42Z DEBUG default_range: ipaDomainIDRange entry found, skip plugin 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_default_trust_view 2025-05-07T18:06:42Z DEBUG raw: update_default_trust_view 2025-05-07T18:06:42Z DEBUG raw: adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG AD Trusts are not enabled on this server 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_tdo_gidnumber 2025-05-07T18:06:42Z DEBUG raw: update_tdo_gidnumber 2025-05-07T18:06:42Z DEBUG raw: adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG AD Trusts are not enabled on this server 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_tdo_to_new_layout 2025-05-07T18:06:42Z DEBUG raw: update_tdo_to_new_layout 2025-05-07T18:06:42Z DEBUG raw: adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG AD Trusts are not enabled on this server 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_host_cifs_keytabs 2025-05-07T18:06:42Z DEBUG raw: update_host_cifs_keytabs 2025-05-07T18:06:42Z DEBUG raw: adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG AD Trusts are not enabled on this server 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_tdo_default_read_keys_permissions 2025-05-07T18:06:42Z DEBUG raw: update_tdo_default_read_keys_permissions 2025-05-07T18:06:42Z DEBUG raw: adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG AD Trusts are not enabled on this server 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_adtrust_agents_members 2025-05-07T18:06:42Z DEBUG raw: update_adtrust_agents_members 2025-05-07T18:06:42Z DEBUG raw: adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG adtrust_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG AD Trusts are not enabled on this server 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_ca_renewal_master 2025-05-07T18:06:42Z DEBUG raw: update_ca_renewal_master 2025-05-07T18:06:42Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:06:42Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:06:42Z DEBUG found CA renewal master master.ufreeipa.test 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_idrange_type 2025-05-07T18:06:42Z DEBUG raw: update_idrange_type 2025-05-07T18:06:42Z DEBUG update_idrange_type: search for ID ranges with no type set 2025-05-07T18:06:42Z DEBUG update_idrange_type: no ID range without type set found 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_pacs 2025-05-07T18:06:42Z DEBUG raw: update_pacs 2025-05-07T18:06:42Z DEBUG Adding nfs:NONE to default PAC types 2025-05-07T18:06:42Z DEBUG update_entry modlist [(0, 'ipakrbauthzdata', [b'nfs:NONE'])] 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_service_principalalias 2025-05-07T18:06:42Z DEBUG raw: update_service_principalalias 2025-05-07T18:06:42Z DEBUG update_service_principalalias: search for affected services 2025-05-07T18:06:42Z DEBUG update_service_principalalias: found 2 services to update, truncated: False 2025-05-07T18:06:42Z DEBUG update_entry modlist [(2, 'ipakrbprincipalalias', [b'ldap/master.ufreeipa.test@UFREEIPA.TEST']), (0, 'objectclass', [b'ipakrbprincipal'])] 2025-05-07T18:06:42Z DEBUG update_entry modlist [(2, 'ipakrbprincipalalias', [b'dogtag/master.ufreeipa.test@UFREEIPA.TEST']), (0, 'objectclass', [b'ipakrbprincipal'])] 2025-05-07T18:06:42Z DEBUG update_service_principalalias: all affected services updated 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_fix_duplicate_cacrt_in_ldap 2025-05-07T18:06:42Z DEBUG raw: update_fix_duplicate_cacrt_in_ldap 2025-05-07T18:06:42Z DEBUG raw: ca_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG ca_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG No duplicates for IPA CA in LDAP 2025-05-07T18:06:42Z DEBUG Executing upgrade plugin: update_upload_cacrt 2025-05-07T18:06:42Z DEBUG raw: update_upload_cacrt 2025-05-07T18:06:42Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:06:42Z DEBUG raw: ca_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG ca_is_enabled(version='2.254') 2025-05-07T18:06:42Z DEBUG Starting external process 2025-05-07T18:06:42Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-UFREEIPA-TEST/', '-L', '-f', '/etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt'] 2025-05-07T18:06:42Z DEBUG Process finished, return code=0 2025-05-07T18:06:42Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI UFREEIPA.TEST IPA CA CT,C,C Server-Cert u,u,u 2025-05-07T18:06:42Z DEBUG stderr= 2025-05-07T18:06:42Z DEBUG Starting external process 2025-05-07T18:06:42Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-UFREEIPA-TEST/', '-L', '-n', 'UFREEIPA.TEST IPA CA', '-a', '-f', '/etc/dirsrv/slapd-UFREEIPA-TEST/pwdfile.txt'] 2025-05-07T18:06:42Z DEBUG Process finished, return code=0 2025-05-07T18:06:42Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIEXTCCAsWgAwIBAgIQRPlllWA6+7XCLLmoASyx1TANBgkqhkiG9w0BAQsFADA4 MRYwFAYDVQQKDA1VRlJFRUlQQS5URVNUMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBB dXRob3JpdHkwHhcNMjUwNTA3MTgwMzI5WhcNNDUwNTA3MTgwMzI5WjA4MRYwFAYD VQQKDA1VRlJFRUlQQS5URVNUMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3Jp dHkwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQC3wl3AJpV/m/VC7mWR mH+ywIvob70Z0bt+tAsXloryNPf29ArIVSlIx8rZhMBRRnz++DS2Bp3AW90HFrr/ 7bZGdwONKpqn2F7s/99NP2xmAzlndKZAnIepRh2bRvJrRKCI2rrvnCd+LE5dB8Hg nTDZHF51iMIuDALQrMp0cLXeYHEWcF4PFqAIDI3cwIJGVyfUJAGb0Q0+8VD9Jp4q avNJbbUv+vNbTuIe+njISITVp1/TmbG244LsE2ki3i4hneytkRPm9pJOLYP1WuYy nNjcoZYubziXDa8rtnKogWlgBoiaFM4tmb8an5kUZ87QWiiUYmCny2KP9azKB199 f+Boy7+tpnnS78DHL1JZGfPoMlHp6IXo30zlWJ7VPEuMtSxgRBaQ5p6QlIUVhDOT eLAN5+daT7aN4+4IWA6+Gz1Vgc4Rg+yxEYtCVeKPRKALQbtGJHe2lOo0xtaJmlHS Ruv/zpicgzOddlcBDZN5x1GVxllLtUE0lWWMFHVEEFC/V10CAwEAAaNjMGEwHQYD VR0OBBYEFAb4otKUM95HEMV4ddBDTIlHqY1sMB8GA1UdIwQYMBaAFAb4otKUM95H EMV4ddBDTIlHqY1sMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgHGMA0G CSqGSIb3DQEBCwUAA4IBgQC3PCA8UkLxH5FegYS2/eZWiXTw0Mb01szLmcPxfL2B D8ZphdroqJ3PXcp5O4Xk2CXEKkHu7+iu2hzQNzdvBrYwVCgWgC8t34qa0QAs01NJ 1797G7A0UVFy1Ahagd39zDeTEMM5SI6mKLkX4S8X8O1k0DUUab2JOEYZS/nqaUnF n3bjzd0In8N7BhxLkw4xNTsNus5t49/rwiJJfTxdO7w/FBD7FbXMWSq+SX2RK+XN jiq8DiAhaOIGjdgv/9/ma4nMOyOmExIzAfl0B3255bQC2H2UUFRMypYEXfUKZHs4 aOJpC0ddz5DGbaRPMqrwhVYRBsKD+CGrzwVL6BNa4xaHQoGd9PUTUWXZvm9Tm78j TsqGIiqF6Gy2E0ZJWnqZD3PyidZ3lhAtaawGZIhJGFa5yMlA7zRIYYgmby0WeQFU hYyEaUm5A1teFNAGpLwHlgjXuw7FtV4OK6WU8iF38KNzPFK2HRfCsYreaQDlECmW edeoS8lqbCBz8pF9xrvNwZE= -----END CERTIFICATE----- 2025-05-07T18:06:42Z DEBUG stderr= 2025-05-07T18:06:42Z DEBUG update_entry modlist [(2, 'ipaCertSubject', [b'CN=Certificate Authority,O=UFREEIPA.TEST']), (2, 'ipaKeyExtUsage', [b'1.3.6.1.5.5.7.3.3', b'1.3.6.1.5.5.7.3.4', b'1.3.6.1.5.5.7.3.1', b'1.3.6.1.5.5.7.3.2']), (2, 'cACertificate;binary', [b'0\x82\x04]0\x82\x02\xc5\xa0\x03\x02\x01\x02\x02\x10D\xf9e\x95`:\xfb\xb5\xc2,\xb9\xa8\x01,\xb1\xd50\r\x06\t*\x86H\x86\xf7\r\x01\x01\x0b\x05\x00081\x160\x14\x06\x03U\x04\n\x0c\rUFREEIPA.TEST1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x1e\x17\r250507180329Z\x17\r450507180329Z081\x160\x14\x06\x03U\x04\n\x0c\rUFREEIPA.TEST1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x82\x01\xa20\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x82\x01\x8f\x000\x82\x01\x8a\x02\x82\x01\x81\x00\xb7\xc2]\xc0&\x95\x7f\x9b\xf5B\xeee\x91\x98\x7f\xb2\xc0\x8b\xe8o\xbd\x19\xd1\xbb~\xb4\x0b\x17\x96\x8a\xf24\xf7\xf6\xf4\n\xc8U)H\xc7\xca\xd9\x84\xc0QF|\xfe\xf84\xb6\x06\x9d\xc0[\xdd\x07\x16\xba\xff\xed\xb6Fw\x03\x8d*\x9a\xa7\xd8^\xec\xff\xdfM?lf\x039gt\xa6@\x9c\x87\xa9F\x1d\x9bF\xf2kD\xa0\x88\xda\xba\xef\x9c\'~,N]\x07\xc1\xe0\x9d0\xd9\x1c^u\x88\xc2.\x0c\x02\xd0\xac\xcatp\xb5\xde`q\x16p^\x0f\x16\xa0\x08\x0c\x8d\xdc\xc0\x82FW\'\xd4$\x01\x9b\xd1\r>\xf1P\xfd&\x9e*j\xf3Im\xb5/\xfa\xf3[N\xe2\x1e\xfax\xc8H\x84\xd5\xa7_\xd3\x99\xb1\xb6\xe3\x82\xec\x13i"\xde.!\x9d\xec\xad\x91\x13\xe6\xf6\x92N-\x83\xf5Z\xe62\x9c\xd8\xdc\xa1\x96.o8\x97\r\xaf+\xb6r\xa8\x81i`\x06\x88\x9a\x14\xce-\x99\xbf\x1a\x9f\x99\x14g\xce\xd0Z(\x94b`\xa7\xcbb\x8f\xf5\xac\xca\x07_}\x7f\xe0h\xcb\xbf\xad\xa6y\xd2\xef\xc0\xc7/RY\x19\xf3\xe82Q\xe9\xe8\x85\xe8\xdfL\xe5X\x9e\xd5\xf1P\xfd&\x9e*j\xf3Im\xb5/\xfa\xf3[N\xe2\x1e\xfax\xc8H\x84\xd5\xa7_\xd3\x99\xb1\xb6\xe3\x82\xec\x13i"\xde.!\x9d\xec\xad\x91\x13\xe6\xf6\x92N-\x83\xf5Z\xe62\x9c\xd8\xdc\xa1\x96.o8\x97\r\xaf+\xb6r\xa8\x81i`\x06\x88\x9a\x14\xce-\x99\xbf\x1a\x9f\x99\x14g\xce\xd0Z(\x94b`\xa7\xcbb\x8f\xf5\xac\xca\x07_}\x7f\xe0h\xcb\xbf\xad\xa6y\xd2\xef\xc0\xc7/RY\x19\xf3\xe82Q\xe9\xe8\x85\xe8\xdfL\xe5X\x9e\xd5 2025-05-07T18:07:00Z DEBUG Parsing update file '/usr/share/ipa/subid-generators.uldif' 2025-05-07T18:07:00Z DEBUG Updating existing entry: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG --------------------------------------------- 2025-05-07T18:07:00Z DEBUG Initial value 2025-05-07T18:07:00Z DEBUG dn: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG objectClass: 2025-05-07T18:07:00Z DEBUG nsContainer 2025-05-07T18:07:00Z DEBUG top 2025-05-07T18:07:00Z DEBUG cn: 2025-05-07T18:07:00Z DEBUG subordinate-ids 2025-05-07T18:07:00Z DEBUG --------------------------------------------- 2025-05-07T18:07:00Z DEBUG Final value after applying updates 2025-05-07T18:07:00Z DEBUG dn: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG objectClass: 2025-05-07T18:07:00Z DEBUG nsContainer 2025-05-07T18:07:00Z DEBUG top 2025-05-07T18:07:00Z DEBUG cn: 2025-05-07T18:07:00Z DEBUG subordinate-ids 2025-05-07T18:07:00Z DEBUG [] 2025-05-07T18:07:00Z DEBUG Updated 0 2025-05-07T18:07:00Z DEBUG Done 2025-05-07T18:07:00Z DEBUG Updating existing entry: cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:07:00Z DEBUG --------------------------------------------- 2025-05-07T18:07:00Z DEBUG Initial value 2025-05-07T18:07:00Z DEBUG dn: cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:07:00Z DEBUG cn: 2025-05-07T18:07:00Z DEBUG Subordinate IDs 2025-05-07T18:07:00Z DEBUG dnaExcludeScope: 2025-05-07T18:07:00Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG dnaFilter: 2025-05-07T18:07:00Z DEBUG (objectClass=ipaSubordinateId) 2025-05-07T18:07:00Z DEBUG dnaInterval: 2025-05-07T18:07:00Z DEBUG 65536 2025-05-07T18:07:00Z DEBUG dnaMagicRegen: 2025-05-07T18:07:00Z DEBUG -1 2025-05-07T18:07:00Z DEBUG dnaMaxValue: 2025-05-07T18:07:00Z DEBUG 4294836224 2025-05-07T18:07:00Z DEBUG dnaNextValue: 2025-05-07T18:07:00Z DEBUG 2147483648 2025-05-07T18:07:00Z DEBUG dnaScope: 2025-05-07T18:07:00Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG dnaSharedCfgDN: 2025-05-07T18:07:00Z DEBUG cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG dnaThreshold: 2025-05-07T18:07:00Z DEBUG 500 2025-05-07T18:07:00Z DEBUG dnaType: 2025-05-07T18:07:00Z DEBUG ipasubuidnumber 2025-05-07T18:07:00Z DEBUG ipasubgidnumber 2025-05-07T18:07:00Z DEBUG objectClass: 2025-05-07T18:07:00Z DEBUG top 2025-05-07T18:07:00Z DEBUG extensibleObject 2025-05-07T18:07:00Z DEBUG add: '(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value [] 2025-05-07T18:07:00Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:07:00Z DEBUG add: '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)' to aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:07:00Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'] 2025-05-07T18:07:00Z DEBUG --------------------------------------------- 2025-05-07T18:07:00Z DEBUG Final value after applying updates 2025-05-07T18:07:00Z DEBUG dn: cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:07:00Z DEBUG cn: 2025-05-07T18:07:00Z DEBUG Subordinate IDs 2025-05-07T18:07:00Z DEBUG dnaExcludeScope: 2025-05-07T18:07:00Z DEBUG cn=provisioning,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG dnaFilter: 2025-05-07T18:07:00Z DEBUG (objectClass=ipaSubordinateId) 2025-05-07T18:07:00Z DEBUG dnaInterval: 2025-05-07T18:07:00Z DEBUG 65536 2025-05-07T18:07:00Z DEBUG dnaMagicRegen: 2025-05-07T18:07:00Z DEBUG -1 2025-05-07T18:07:00Z DEBUG dnaMaxValue: 2025-05-07T18:07:00Z DEBUG 4294836224 2025-05-07T18:07:00Z DEBUG dnaNextValue: 2025-05-07T18:07:00Z DEBUG 2147483648 2025-05-07T18:07:00Z DEBUG dnaScope: 2025-05-07T18:07:00Z DEBUG dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG dnaSharedCfgDN: 2025-05-07T18:07:00Z DEBUG cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG dnaThreshold: 2025-05-07T18:07:00Z DEBUG 500 2025-05-07T18:07:00Z DEBUG dnaType: 2025-05-07T18:07:00Z DEBUG ipasubuidnumber 2025-05-07T18:07:00Z DEBUG ipasubgidnumber 2025-05-07T18:07:00Z DEBUG objectClass: 2025-05-07T18:07:00Z DEBUG top 2025-05-07T18:07:00Z DEBUG extensibleObject 2025-05-07T18:07:00Z DEBUG aci: 2025-05-07T18:07:00Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:07:00Z DEBUG (targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";) 2025-05-07T18:07:00Z DEBUG [(2, 'aci', ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:07:00Z DEBUG Updated 1 2025-05-07T18:07:00Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)', b'(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ufreeipa,dc=test";)'])] 2025-05-07T18:07:00Z DEBUG Done 2025-05-07T18:07:00Z DEBUG Updating existing entry: cn=UFREEIPA.TEST_subid_range,cn=ranges,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG --------------------------------------------- 2025-05-07T18:07:00Z DEBUG Initial value 2025-05-07T18:07:00Z DEBUG dn: cn=UFREEIPA.TEST_subid_range,cn=ranges,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG objectClass: 2025-05-07T18:07:00Z DEBUG top 2025-05-07T18:07:00Z DEBUG ipaIDrange 2025-05-07T18:07:00Z DEBUG ipaTrustedADDomainRange 2025-05-07T18:07:00Z DEBUG cn: 2025-05-07T18:07:00Z DEBUG UFREEIPA.TEST_subid_range 2025-05-07T18:07:00Z DEBUG ipaBaseID: 2025-05-07T18:07:00Z DEBUG 2147483648 2025-05-07T18:07:00Z DEBUG ipaIDRangeSize: 2025-05-07T18:07:00Z DEBUG 2147352576 2025-05-07T18:07:00Z DEBUG ipaBaseRID: 2025-05-07T18:07:00Z DEBUG 2147283648 2025-05-07T18:07:00Z DEBUG ipaNTTrustedDomainSID: 2025-05-07T18:07:00Z DEBUG S-1-5-21-738065-838566-412112059 2025-05-07T18:07:00Z DEBUG ipaRangeType: 2025-05-07T18:07:00Z DEBUG ipa-ad-trust 2025-05-07T18:07:00Z DEBUG --------------------------------------------- 2025-05-07T18:07:00Z DEBUG Final value after applying updates 2025-05-07T18:07:00Z DEBUG dn: cn=UFREEIPA.TEST_subid_range,cn=ranges,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG objectClass: 2025-05-07T18:07:00Z DEBUG top 2025-05-07T18:07:00Z DEBUG ipaIDrange 2025-05-07T18:07:00Z DEBUG ipaTrustedADDomainRange 2025-05-07T18:07:00Z DEBUG cn: 2025-05-07T18:07:00Z DEBUG UFREEIPA.TEST_subid_range 2025-05-07T18:07:00Z DEBUG ipaBaseID: 2025-05-07T18:07:00Z DEBUG 2147483648 2025-05-07T18:07:00Z DEBUG ipaIDRangeSize: 2025-05-07T18:07:00Z DEBUG 2147352576 2025-05-07T18:07:00Z DEBUG ipaBaseRID: 2025-05-07T18:07:00Z DEBUG 2147283648 2025-05-07T18:07:00Z DEBUG ipaNTTrustedDomainSID: 2025-05-07T18:07:00Z DEBUG S-1-5-21-738065-838566-412112059 2025-05-07T18:07:00Z DEBUG ipaRangeType: 2025-05-07T18:07:00Z DEBUG ipa-ad-trust 2025-05-07T18:07:00Z DEBUG [] 2025-05-07T18:07:00Z DEBUG Updated 0 2025-05-07T18:07:00Z DEBUG Done 2025-05-07T18:07:00Z DEBUG LDAP update duration: /usr/share/ipa/subid-generators.uldif 0.380 sec 2025-05-07T18:07:00Z DEBUG Destroyed connection context.ldap2_139937081761024 2025-05-07T18:07:00Z DEBUG Executing upgrade plugin: update_idrange_baserid 2025-05-07T18:07:00Z DEBUG raw: update_idrange_baserid 2025-05-07T18:07:00Z DEBUG update_idrange_baserid: search for ipa-ad-trust-posix ID ranges with ipaBaseRID != 0 2025-05-07T18:07:00Z DEBUG update_idrange_baserid: no AD domain range with posix attributes found 2025-05-07T18:07:00Z DEBUG Executing upgrade plugin: update_passync_privilege_update 2025-05-07T18:07:00Z DEBUG raw: update_passync_privilege_update 2025-05-07T18:07:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:00Z DEBUG Add PassSync user as a member of PassSync privilege 2025-05-07T18:07:00Z DEBUG PassSync user not found, no update needed 2025-05-07T18:07:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:00Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:00Z DEBUG Executing upgrade plugin: update_dnsserver_configuration_into_ldap 2025-05-07T18:07:00Z DEBUG raw: update_dnsserver_configuration_into_ldap 2025-05-07T18:07:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:00Z DEBUG DNS container not found, nothing to upgrade 2025-05-07T18:07:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:00Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:00Z DEBUG Executing upgrade plugin: update_ldap_server_list 2025-05-07T18:07:00Z DEBUG raw: update_ldap_server_list 2025-05-07T18:07:00Z DEBUG Executing upgrade plugin: update_dna_shared_config 2025-05-07T18:07:00Z DEBUG raw: update_dna_shared_config 2025-05-07T18:07:00Z DEBUG Found DNA config cn=posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:07:00Z DEBUG dnaSharedCfgDN: cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG update_entry modlist [(2, 'dnaRemoteBindMethod', [b'SASL/GSSAPI']), (2, 'dnaRemoteConnProtocol', [b'LDAP'])] 2025-05-07T18:07:00Z DEBUG Updated entry dnaHostname=master.ufreeipa.test+dnaPortNum=389,cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG update_entry modlist [(2, 'dnaRemoteBindMethod', [b'SASL/GSSAPI']), (2, 'dnaRemoteConnProtocol', [b'LDAP'])] 2025-05-07T18:07:00Z DEBUG Updated entry dnaHostname=master.ufreeipa.test+dnaPortNum=0,cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG Found DNA config cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2025-05-07T18:07:00Z DEBUG dnaSharedCfgDN: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG update_entry modlist [(2, 'dnaRemoteBindMethod', [b'SASL/GSSAPI']), (2, 'dnaRemoteConnProtocol', [b'LDAP'])] 2025-05-07T18:07:00Z DEBUG Updated entry dnaHostname=master.ufreeipa.test+dnaPortNum=389,cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG update_entry modlist [(2, 'dnaRemoteBindMethod', [b'SASL/GSSAPI']), (2, 'dnaRemoteConnProtocol', [b'LDAP'])] 2025-05-07T18:07:00Z DEBUG Updated entry dnaHostname=master.ufreeipa.test+dnaPortNum=0,cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=ufreeipa,dc=test 2025-05-07T18:07:00Z DEBUG Executing upgrade plugin: update_unhashed_password 2025-05-07T18:07:00Z DEBUG raw: update_unhashed_password 2025-05-07T18:07:00Z DEBUG Upgrading unhashed password configuration 2025-05-07T18:07:00Z DEBUG Unhashed password this is not a winsync deployment 2025-05-07T18:07:00Z DEBUG Executing upgrade plugin: update_krb_uri_txt_records_for_locations 2025-05-07T18:07:00Z DEBUG raw: update_krb_uri_txt_records_for_locations 2025-05-07T18:07:00Z DEBUG LDAP update duration: /usr/share/ipa/updates/90-post_upgrade_plugins.update 19.605 sec 2025-05-07T18:07:00Z DEBUG Destroyed connection context.ldap2_139937118245168 2025-05-07T18:07:00Z DEBUG step duration: dirsrv __upgrade 32.39 sec 2025-05-07T18:07:00Z DEBUG [8/10]: stopping directory server 2025-05-07T18:07:00Z DEBUG Destroyed connection context.ldap2_139937138938208 2025-05-07T18:07:00Z DEBUG Starting external process 2025-05-07T18:07:00Z DEBUG args=['/bin/systemctl', 'stop', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:07:01Z DEBUG Process finished, return code=0 2025-05-07T18:07:01Z DEBUG stdout= 2025-05-07T18:07:01Z DEBUG stderr= 2025-05-07T18:07:01Z DEBUG Stop of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:07:01Z DEBUG step duration: dirsrv __stop_instance 0.43 sec 2025-05-07T18:07:01Z DEBUG [9/10]: restoring configuration 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:01Z DEBUG step duration: dirsrv __restore_config 0.04 sec 2025-05-07T18:07:01Z DEBUG [10/10]: starting directory server 2025-05-07T18:07:01Z DEBUG Starting external process 2025-05-07T18:07:01Z DEBUG args=['/bin/systemctl', 'start', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:07:02Z DEBUG Process finished, return code=0 2025-05-07T18:07:02Z DEBUG stdout= 2025-05-07T18:07:02Z DEBUG stderr= 2025-05-07T18:07:02Z DEBUG Start of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:07:03Z DEBUG Created connection context.ldap2_139937138938208 2025-05-07T18:07:03Z DEBUG step duration: dirsrv __start 1.63 sec 2025-05-07T18:07:03Z DEBUG Done. 2025-05-07T18:07:03Z DEBUG service duration: dirsrv 36.04 sec 2025-05-07T18:07:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:03Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:03Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:03Z DEBUG Restarting the KDC 2025-05-07T18:07:03Z DEBUG Starting external process 2025-05-07T18:07:03Z DEBUG args=['/bin/systemctl', 'restart', 'krb5kdc.service'] 2025-05-07T18:07:03Z DEBUG Process finished, return code=0 2025-05-07T18:07:03Z DEBUG stdout= 2025-05-07T18:07:03Z DEBUG stderr= 2025-05-07T18:07:03Z DEBUG Starting external process 2025-05-07T18:07:03Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2025-05-07T18:07:03Z DEBUG Process finished, return code=0 2025-05-07T18:07:03Z DEBUG stdout=active 2025-05-07T18:07:03Z DEBUG stderr= 2025-05-07T18:07:03Z DEBUG Restart of krb5kdc.service complete 2025-05-07T18:07:03Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:07:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:03Z INFO dnssec-validation yes 2025-05-07T18:07:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:03Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:03Z DEBUG Starting external process 2025-05-07T18:07:03Z DEBUG args=['/bin/systemctl', 'stop', 'named.service'] 2025-05-07T18:07:03Z DEBUG Process finished, return code=0 2025-05-07T18:07:03Z DEBUG stdout= 2025-05-07T18:07:03Z DEBUG stderr= 2025-05-07T18:07:03Z DEBUG Stop of named.service complete 2025-05-07T18:07:03Z DEBUG raw: dnszone_show('ufreeipa.test', version='2.254') 2025-05-07T18:07:03Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:03Z DEBUG Configuring DNS (named) 2025-05-07T18:07:03Z DEBUG [1/12]: generating rndc key file 2025-05-07T18:07:03Z DEBUG Starting external process 2025-05-07T18:07:03Z DEBUG args=['/usr/libexec/generate-rndc-key.sh'] 2025-05-07T18:07:03Z DEBUG Process finished, return code=0 2025-05-07T18:07:03Z DEBUG stdout=Generating /etc/rndc.key: OK 2025-05-07T18:07:03Z DEBUG stderr= 2025-05-07T18:07:03Z DEBUG step duration: named __generate_rndc_key 0.05 sec 2025-05-07T18:07:03Z DEBUG [2/12]: adding DNS container 2025-05-07T18:07:03Z DEBUG Starting external process 2025-05-07T18:07:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpk6gmb2ct', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:07:03Z DEBUG Process finished, return code=0 2025-05-07T18:07:03Z DEBUG stdout=add objectClass: idnsConfigObject nsContainer ipaConfigObject ipaDNSContainer top add cn: dns add ipaConfigString: DNSVersion 1 add ipaDNSVersion: 2 add aci: (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) (target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) (target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ufreeipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) (targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ufreeipa,dc=test";) adding new entry "cn=dns,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: servers adding new entry "cn=servers,cn=dns,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:07:03Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:07:03Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:07:03Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:07:05Z DEBUG step duration: named __setup_dns_container 1.50 sec 2025-05-07T18:07:05Z DEBUG [3/12]: setting up our zone 2025-05-07T18:07:05Z DEBUG raw: dnszone_add('ufreeipa.test.', idnssoamname='master.ufreeipa.test.', idnssoarname='hostmaster.ufreeipa.test.', idnsupdatepolicy='grant UFREEIPA.TEST krb5-self * A; grant UFREEIPA.TEST krb5-self * AAAA; grant UFREEIPA.TEST krb5-self * SSHFP;', idnsallowdynupdate=True, idnsallowquery='any', idnsallowtransfer='none', skip_overlap_check=True, force=True, version='2.254') 2025-05-07T18:07:05Z DEBUG dnszone_add(, idnssoamname=, idnssoarname=, idnssoarefresh=3600, idnssoaretry=900, idnssoaexpire=1209600, idnssoaminimum=3600, idnsupdatepolicy='grant UFREEIPA.TEST krb5-self * A; grant UFREEIPA.TEST krb5-self * AAAA; grant UFREEIPA.TEST krb5-self * SSHFP;', idnsallowdynupdate=True, idnsallowquery='any;', idnsallowtransfer='none;', skip_overlap_check=True, force=True, skip_nameserver_check=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG raw: dnsrecord_add('ufreeipa.test', '_kerberos', txtrecord='UFREEIPA.TEST', version='2.254') 2025-05-07T18:07:05Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, txtrecord=('UFREEIPA.TEST',), force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG step duration: named __setup_zone 0.19 sec 2025-05-07T18:07:05Z DEBUG [4/12]: setting up our own record 2025-05-07T18:07:05Z DEBUG raw: dnszone_show('ufreeipa.test', version='2.254') 2025-05-07T18:07:05Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG raw: dnsrecord_add('ufreeipa.test', 'master', arecord='10.0.169.172', version='2.254') 2025-05-07T18:07:05Z DEBUG dnsrecord_add(, , arecord=('10.0.169.172',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG raw: dnszone_show('172.169.0.10.in-addr.arpa.', version='2.254') 2025-05-07T18:07:05Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG raw: dnszone_show('169.0.10.in-addr.arpa.', version='2.254') 2025-05-07T18:07:05Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG raw: dnszone_show('0.10.in-addr.arpa.', version='2.254') 2025-05-07T18:07:05Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG raw: dnszone_show('10.in-addr.arpa.', version='2.254') 2025-05-07T18:07:05Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG raw: dnszone_show('in-addr.arpa.', version='2.254') 2025-05-07T18:07:05Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG raw: dnszone_show('arpa.', version='2.254') 2025-05-07T18:07:05Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG step duration: named __add_self 0.22 sec 2025-05-07T18:07:05Z DEBUG [5/12]: setting up records for other masters 2025-05-07T18:07:05Z DEBUG step duration: named __add_others 0.00 sec 2025-05-07T18:07:05Z DEBUG [6/12]: adding NS record to the zones 2025-05-07T18:07:05Z DEBUG raw: dnszone_find(None, version='2.254') 2025-05-07T18:07:05Z DEBUG dnszone_find(None, forward_only=False, all=False, raw=False, version='2.254', pkey_only=False) 2025-05-07T18:07:05Z DEBUG adding self NS to zone ufreeipa.test. apex 2025-05-07T18:07:05Z DEBUG raw: dnsrecord_add('ufreeipa.test.', '@', nsrecord='master.ufreeipa.test.', force=True, version='2.254') 2025-05-07T18:07:05Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, nsrecord=('master.ufreeipa.test.',), force=True, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:05Z DEBUG update_entry modlist [(2, 'nsrecord', [b'master.ufreeipa.test.'])] 2025-05-07T18:07:05Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:05Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:05Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:05Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:05Z DEBUG step duration: named __add_self_ns 0.15 sec 2025-05-07T18:07:05Z DEBUG [7/12]: setting up kerberos principal 2025-05-07T18:07:05Z DEBUG Starting external process 2025-05-07T18:07:05Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey DNS/master.ufreeipa.test@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:07:06Z DEBUG Process finished, return code=0 2025-05-07T18:07:06Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Principal "DNS/master.ufreeipa.test@UFREEIPA.TEST" created. 2025-05-07T18:07:06Z DEBUG stderr=No policy specified for DNS/master.ufreeipa.test@UFREEIPA.TEST; defaulting to no policy 2025-05-07T18:07:06Z DEBUG Backing up system configuration file '/etc/named.keytab' 2025-05-07T18:07:06Z DEBUG -> Not backing up - '/etc/named.keytab' doesn't exist 2025-05-07T18:07:06Z DEBUG Starting external process 2025-05-07T18:07:06Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/named.keytab DNS/master.ufreeipa.test@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:07:06Z DEBUG Process finished, return code=0 2025-05-07T18:07:06Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Entry for principal DNS/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/named.keytab. 2025-05-07T18:07:06Z DEBUG stderr= 2025-05-07T18:07:06Z DEBUG step duration: named __setup_principal 1.18 sec 2025-05-07T18:07:06Z DEBUG [8/12]: setting up LDAPI autobind 2025-05-07T18:07:06Z DEBUG Created autobind entry cn=named,cn=auto_bind,cn=config 2025-05-07T18:07:06Z DEBUG Creating reload task cn=reload_1746641226,cn=reload ldapi mappings,cn=tasks,cn=config 2025-05-07T18:07:19Z DEBUG Task cn=reload_1746641226,cn=reload ldapi mappings,cn=tasks,cn=config has finished with exit code 0 2025-05-07T18:07:19Z DEBUG step duration: named setup_autobind 12.18 sec 2025-05-07T18:07:19Z DEBUG [9/12]: setting up named.conf 2025-05-07T18:07:19Z DEBUG Backing up system configuration file '/etc/named.conf' 2025-05-07T18:07:19Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:07:19Z INFO created new /etc/named.conf 2025-05-07T18:07:19Z INFO created named user config '/etc/named/ipa-ext.conf' 2025-05-07T18:07:19Z INFO created named user config '/etc/named/ipa-options-ext.conf' 2025-05-07T18:07:19Z INFO created named user config '/etc/named/ipa-logging-ext.conf' 2025-05-07T18:07:19Z DEBUG step duration: named setup_named_conf 0.00 sec 2025-05-07T18:07:19Z DEBUG [10/12]: setting up server configuration 2025-05-07T18:07:19Z DEBUG cn=servers,cn=dns container already exists 2025-05-07T18:07:19Z DEBUG raw: dnsserver_add('master.ufreeipa.test', idnssoamname=, version='2.254') 2025-05-07T18:07:19Z DEBUG dnsserver_add('master.ufreeipa.test', idnssoamname=, all=False, raw=False, version='2.254') 2025-05-07T18:07:19Z DEBUG raw: dnsserver_mod('master.ufreeipa.test', idnsforwarders=['10.11.5.19'], idnsforwardpolicy='only', version='2.254') 2025-05-07T18:07:19Z DEBUG dnsserver_mod('master.ufreeipa.test', idnsforwarders=('10.11.5.19',), idnsforwardpolicy='only', rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:19Z DEBUG update_entry modlist [(2, 'idnsforwardpolicy', [b'only']), (2, 'idnsforwarders', [b'10.11.5.19'])] 2025-05-07T18:07:19Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:19Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2025-05-07T18:07:19Z DEBUG step duration: named __setup_server_configuration 0.07 sec 2025-05-07T18:07:19Z DEBUG [11/12]: configuring named to start on boot 2025-05-07T18:07:19Z DEBUG Starting external process 2025-05-07T18:07:19Z DEBUG args=['/bin/systemctl', 'stop', 'named-pkcs11.service'] 2025-05-07T18:07:19Z DEBUG Process finished, return code=5 2025-05-07T18:07:19Z DEBUG stdout= 2025-05-07T18:07:19Z DEBUG stderr=Failed to stop named-pkcs11.service: Unit named-pkcs11.service not loaded. 2025-05-07T18:07:19Z DEBUG Unable to stop named-pkcs11.service (CalledProcessError(Command ['/bin/systemctl', 'stop', 'named-pkcs11.service'] returned non-zero exit status 5: 'Failed to stop named-pkcs11.service: Unit named-pkcs11.service not loaded.\n')) 2025-05-07T18:07:19Z DEBUG Starting external process 2025-05-07T18:07:19Z DEBUG args=['/bin/systemctl', 'mask', 'named-pkcs11.service'] 2025-05-07T18:07:19Z DEBUG Process finished, return code=0 2025-05-07T18:07:19Z DEBUG stdout= 2025-05-07T18:07:19Z DEBUG stderr=Unit named-pkcs11.service does not exist, proceeding anyway. Created symlink '/etc/systemd/system/named-pkcs11.service' → '/dev/null'. 2025-05-07T18:07:19Z DEBUG Starting external process 2025-05-07T18:07:19Z DEBUG args=['/bin/systemctl', 'unmask', 'named.service'] 2025-05-07T18:07:19Z DEBUG Process finished, return code=0 2025-05-07T18:07:19Z DEBUG stdout= 2025-05-07T18:07:19Z DEBUG stderr= 2025-05-07T18:07:19Z DEBUG Starting external process 2025-05-07T18:07:19Z DEBUG args=['/bin/systemctl', 'disable', 'named.service'] 2025-05-07T18:07:20Z DEBUG Process finished, return code=0 2025-05-07T18:07:20Z DEBUG stdout= 2025-05-07T18:07:20Z DEBUG stderr= 2025-05-07T18:07:20Z DEBUG step duration: named switch_service 1.12 sec 2025-05-07T18:07:20Z DEBUG [12/12]: changing resolv.conf to point to ourselves 2025-05-07T18:07:20Z DEBUG Backing up system configuration file '/etc/resolv.conf' 2025-05-07T18:07:20Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:07:20Z DEBUG Starting external process 2025-05-07T18:07:20Z DEBUG args=['/bin/systemctl', 'is-enabled', 'NetworkManager.service'] 2025-05-07T18:07:20Z DEBUG Process finished, return code=0 2025-05-07T18:07:20Z DEBUG stdout=enabled 2025-05-07T18:07:20Z DEBUG stderr= 2025-05-07T18:07:20Z DEBUG Network Manager is enabled, write /etc/NetworkManager/conf.d/zzz-ipa.conf 2025-05-07T18:07:20Z DEBUG Starting external process 2025-05-07T18:07:20Z DEBUG args=['/bin/systemctl', 'reload-or-restart', 'NetworkManager.service'] 2025-05-07T18:07:20Z DEBUG Process finished, return code=0 2025-05-07T18:07:20Z DEBUG stdout= 2025-05-07T18:07:20Z DEBUG stderr= 2025-05-07T18:07:20Z DEBUG Starting external process 2025-05-07T18:07:20Z DEBUG args=['/bin/systemctl', 'is-active', 'NetworkManager.service'] 2025-05-07T18:07:20Z DEBUG Process finished, return code=0 2025-05-07T18:07:20Z DEBUG stdout=active 2025-05-07T18:07:20Z DEBUG stderr= 2025-05-07T18:07:20Z DEBUG Restart of NetworkManager.service complete 2025-05-07T18:07:20Z DEBUG step duration: named setup_resolv_conf 0.08 sec 2025-05-07T18:07:20Z DEBUG Done configuring DNS (named). 2025-05-07T18:07:20Z DEBUG service duration: named 16.74 sec 2025-05-07T18:07:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:20Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:20Z DEBUG Starting external process 2025-05-07T18:07:20Z DEBUG args=['/bin/systemctl', 'restart', 'httpd.service'] 2025-05-07T18:07:22Z DEBUG Process finished, return code=0 2025-05-07T18:07:22Z DEBUG stdout= 2025-05-07T18:07:22Z DEBUG stderr= 2025-05-07T18:07:22Z DEBUG Starting external process 2025-05-07T18:07:22Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2025-05-07T18:07:22Z DEBUG Process finished, return code=0 2025-05-07T18:07:22Z DEBUG stdout=active 2025-05-07T18:07:22Z DEBUG stderr= 2025-05-07T18:07:22Z DEBUG Restart of httpd.service complete 2025-05-07T18:07:22Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:22Z DEBUG Starting external process 2025-05-07T18:07:22Z DEBUG args=['/bin/systemctl', 'stop', 'ipa-dnskeysyncd.service'] 2025-05-07T18:07:22Z DEBUG Process finished, return code=0 2025-05-07T18:07:22Z DEBUG stdout= 2025-05-07T18:07:22Z DEBUG stderr= 2025-05-07T18:07:22Z DEBUG Stop of ipa-dnskeysyncd.service complete 2025-05-07T18:07:22Z DEBUG Configuring DNS key synchronization service (ipa-dnskeysyncd) 2025-05-07T18:07:22Z DEBUG [1/7]: checking status 2025-05-07T18:07:22Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:22Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:22Z DEBUG step duration: ipa-dnskeysyncd __check_dnssec_status 0.02 sec 2025-05-07T18:07:22Z DEBUG [2/7]: setting up bind-dyndb-ldap working directory 2025-05-07T18:07:22Z DEBUG step duration: ipa-dnskeysyncd set_dyndb_ldap_workdir_permissions 0.00 sec 2025-05-07T18:07:22Z DEBUG [3/7]: setting up kerberos principal 2025-05-07T18:07:22Z DEBUG Removing service keytab: /etc/ipa/dnssec/ipa-dnskeysyncd.keytab 2025-05-07T18:07:22Z DEBUG Starting external process 2025-05-07T18:07:22Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:07:22Z DEBUG Process finished, return code=0 2025-05-07T18:07:22Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Principal "ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST" created. 2025-05-07T18:07:22Z DEBUG stderr=No policy specified for ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST; defaulting to no policy 2025-05-07T18:07:22Z DEBUG Starting external process 2025-05-07T18:07:22Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/ipa/dnssec/ipa-dnskeysyncd.keytab ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2025-05-07T18:07:23Z DEBUG Process finished, return code=0 2025-05-07T18:07:23Z DEBUG stdout=Authenticating as principal root/admin@UFREEIPA.TEST with password. Entry for principal ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.ufreeipa.test@UFREEIPA.TEST with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. 2025-05-07T18:07:23Z DEBUG stderr= 2025-05-07T18:07:23Z DEBUG step duration: ipa-dnskeysyncd __setup_principal 1.20 sec 2025-05-07T18:07:23Z DEBUG [4/7]: setting up SoftHSM 2025-05-07T18:07:23Z DEBUG Creating /var/lib/ipa/dnssec directory 2025-05-07T18:07:23Z DEBUG Creating new softhsm config file 2025-05-07T18:07:23Z DEBUG Setup OpenSSL config for BIND 2025-05-07T18:07:23Z DEBUG Setup BIND sysconfig 2025-05-07T18:07:23Z DEBUG Backing up system configuration file '/etc/sysconfig/named' 2025-05-07T18:07:23Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:07:23Z DEBUG Setup ipa-dnskeysyncd sysconfig 2025-05-07T18:07:23Z DEBUG Creating tokens /var/lib/ipa/dnssec/tokens directory 2025-05-07T18:07:23Z DEBUG Saving user PIN to /var/lib/ipa/dnssec/softhsm_pin 2025-05-07T18:07:23Z DEBUG Saving SO PIN to /etc/ipa/dnssec/softhsm_pin_so 2025-05-07T18:07:23Z DEBUG Initializing tokens 2025-05-07T18:07:23Z DEBUG Starting external process 2025-05-07T18:07:23Z DEBUG args=['/usr/bin/softhsm2-util', '--init-token', '--free', '--label', 'ipaDNSSEC', '--pin', XXXXXXXX, '--so-pin', XXXXXXXX] 2025-05-07T18:07:23Z DEBUG Process finished, return code=0 2025-05-07T18:07:23Z DEBUG stdout=Slot 0 has a free/uninitialized token. The token has been initialized and is reassigned to slot 1714600641 2025-05-07T18:07:23Z DEBUG stderr= 2025-05-07T18:07:23Z DEBUG step duration: ipa-dnskeysyncd __setup_softhsm 0.02 sec 2025-05-07T18:07:23Z DEBUG [5/7]: adding DNSSEC containers 2025-05-07T18:07:23Z DEBUG Starting external process 2025-05-07T18:07:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpt2ml7umb', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:07:23Z DEBUG Process finished, return code=0 2025-05-07T18:07:23Z DEBUG stdout=add objectClass: nsContainer top add cn: sec adding new entry "cn=sec,cn=dns,dc=ufreeipa,dc=test" modify complete add objectClass: nsContainer top add cn: keys adding new entry "cn=keys,cn=sec,cn=dns,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:07:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:07:23Z DEBUG step duration: ipa-dnskeysyncd __setup_dnssec_containers 0.33 sec 2025-05-07T18:07:23Z DEBUG [6/7]: creating replica keys 2025-05-07T18:07:24Z DEBUG Creating replica's key pair 2025-05-07T18:07:24Z DEBUG Storing replica public key to LDAP, ipk11UniqueId=autogenerate,cn=keys,cn=sec,cn=dns,dc=ufreeipa,dc=test 2025-05-07T18:07:24Z DEBUG Replica public key stored 2025-05-07T18:07:24Z DEBUG Setting CKA_WRAP=False for old replica keys 2025-05-07T18:07:24Z DEBUG Changing ownership of token files 2025-05-07T18:07:24Z DEBUG step duration: ipa-dnskeysyncd __setup_replica_keys 0.21 sec 2025-05-07T18:07:24Z DEBUG [7/7]: configuring ipa-dnskeysyncd to start on boot 2025-05-07T18:07:24Z DEBUG Starting external process 2025-05-07T18:07:24Z DEBUG args=['/bin/systemctl', 'unmask', 'ipa-dnskeysyncd.service'] 2025-05-07T18:07:24Z DEBUG Process finished, return code=0 2025-05-07T18:07:24Z DEBUG stdout= 2025-05-07T18:07:24Z DEBUG stderr= 2025-05-07T18:07:24Z DEBUG Starting external process 2025-05-07T18:07:24Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-dnskeysyncd.service'] 2025-05-07T18:07:25Z DEBUG Process finished, return code=0 2025-05-07T18:07:25Z DEBUG stdout= 2025-05-07T18:07:25Z DEBUG stderr= 2025-05-07T18:07:25Z DEBUG step duration: ipa-dnskeysyncd __enable 1.01 sec 2025-05-07T18:07:25Z DEBUG Done configuring DNS key synchronization service (ipa-dnskeysyncd). 2025-05-07T18:07:25Z DEBUG service duration: ipa-dnskeysyncd 2.79 sec 2025-05-07T18:07:25Z DEBUG Starting external process 2025-05-07T18:07:25Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-dnskeysyncd.service'] 2025-05-07T18:07:25Z DEBUG Process finished, return code=1 2025-05-07T18:07:25Z DEBUG stdout= 2025-05-07T18:07:25Z DEBUG stderr=Job for ipa-dnskeysyncd.service failed because the control process exited with error code. See "systemctl status ipa-dnskeysyncd.service" and "journalctl -xeu ipa-dnskeysyncd.service" for details. 2025-05-07T18:07:25Z DEBUG Failed to start ipa-dnskeysyncd: CalledProcessError(Command ['/bin/systemctl', 'restart', 'ipa-dnskeysyncd.service'] returned non-zero exit status 1: 'Job for ipa-dnskeysyncd.service failed because the control process exited with error code.\nSee "systemctl status ipa-dnskeysyncd.service" and "journalctl -xeu ipa-dnskeysyncd.service" for details.\n') 2025-05-07T18:07:25Z DEBUG Restarting named 2025-05-07T18:07:25Z DEBUG Starting external process 2025-05-07T18:07:25Z DEBUG args=['/bin/systemctl', 'restart', 'named.service'] 2025-05-07T18:07:25Z DEBUG Process finished, return code=0 2025-05-07T18:07:25Z DEBUG stdout= 2025-05-07T18:07:25Z DEBUG stderr= 2025-05-07T18:07:25Z DEBUG Starting external process 2025-05-07T18:07:25Z DEBUG args=['/bin/systemctl', 'is-active', 'named.service'] 2025-05-07T18:07:25Z DEBUG Process finished, return code=0 2025-05-07T18:07:25Z DEBUG stdout=active 2025-05-07T18:07:25Z DEBUG stderr= 2025-05-07T18:07:25Z DEBUG Restart of named.service complete 2025-05-07T18:07:25Z DEBUG Updating DNS system records 2025-05-07T18:07:25Z DEBUG raw: server_find(None, version='2.254', no_members=False, servrole='IPA master') 2025-05-07T18:07:25Z DEBUG server_find(None, all=False, raw=False, version='2.254', no_members=False, pkey_only=False, servrole=('IPA master',)) 2025-05-07T18:07:25Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.254') 2025-05-07T18:07:25Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.254') 2025-05-07T18:07:25Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.254') 2025-05-07T18:07:25Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.254', pkey_only=False) 2025-05-07T18:07:25Z DEBUG raw: dnszone_show(, version='2.254') 2025-05-07T18:07:25Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:25Z DEBUG raw: dnsrecord_del(, , del_all=True, version='2.254') 2025-05-07T18:07:25Z DEBUG dnsrecord_del(, , del_all=True, structured=False, raw=False, version='2.254') 2025-05-07T18:07:25Z DEBUG raw: dnsrecord_delentry(, (,), version='2.254') 2025-05-07T18:07:25Z DEBUG dnsrecord_delentry(, (,), continue=False, version='2.254') 2025-05-07T18:07:25Z DEBUG raw: location_find(None, version='2.254') 2025-05-07T18:07:25Z DEBUG location_find(None, all=False, raw=False, version='2.254', pkey_only=False) 2025-05-07T18:07:25Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:25Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2025-05-07T18:07:25Z DEBUG Configuring SID generation 2025-05-07T18:07:25Z DEBUG [1/8]: adding RID bases 2025-05-07T18:07:25Z DEBUG [LDAPEntry(ipapython.dn.DN('cn=UFREEIPA.TEST_id_range,cn=ranges,cn=etc,dc=ufreeipa,dc=test'), {'objectClass': [b'top', b'ipaIDrange', b'ipaDomainIDRange'], 'cn': [b'UFREEIPA.TEST_id_range'], 'ipaBaseID': [b'63800000'], 'ipaIDRangeSize': [b'200000'], 'ipaRangeType': ['ipa-local']})] 2025-05-07T18:07:25Z DEBUG [LDAPEntry(ipapython.dn.DN('cn=UFREEIPA.TEST_id_range,cn=ranges,cn=etc,dc=ufreeipa,dc=test'), {'objectClass': [b'top', b'ipaIDrange', b'ipaDomainIDRange'], 'cn': [b'UFREEIPA.TEST_id_range'], 'ipaBaseID': [b'63800000'], 'ipaIDRangeSize': [b'200000'], 'ipaRangeType': ['ipa-local']})] 2025-05-07T18:07:25Z DEBUG step duration: SID generation __add_rid_bases 0.03 sec 2025-05-07T18:07:25Z DEBUG [2/8]: creating samba domain object 2025-05-07T18:07:26Z DEBUG step duration: SID generation __create_samba_domain_object 0.11 sec 2025-05-07T18:07:26Z DEBUG [3/8]: adding admin(group) SIDs 2025-05-07T18:07:26Z DEBUG step duration: SID generation __add_admin_sids 0.06 sec 2025-05-07T18:07:26Z DEBUG [4/8]: updating Kerberos config 2025-05-07T18:07:26Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2025-05-07T18:07:26Z DEBUG step duration: SID generation __update_krb5_conf 0.00 sec 2025-05-07T18:07:26Z DEBUG [5/8]: activating sidgen task 2025-05-07T18:07:26Z DEBUG Starting external process 2025-05-07T18:07:26Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpgdrjx6jj', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:07:26Z DEBUG Process finished, return code=0 2025-05-07T18:07:26Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: ipa-sidgen-task add nsslapd-pluginPath: libipa_sidgen_task add nsslapd-pluginInitfunc: sidgen_task_init add nsslapd-pluginType: object add nsslapd-pluginEnabled: on add nsslapd-pluginId: ipa_sidgen_task add nsslapd-pluginVersion: 1.0 add nsslapd-pluginVendor: RedHat add nsslapd-pluginDescription: Generate SIDs for existing user and group entries adding new entry "cn=ipa-sidgen-task,cn=plugins,cn=config" modify complete add objectClass: top extensibleObject add cn: ipa-sidgen-task adding new entry "cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2025-05-07T18:07:26Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:07:26Z DEBUG step duration: SID generation __add_sidgen_task 0.20 sec 2025-05-07T18:07:26Z DEBUG [6/8]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2025-05-07T18:07:26Z DEBUG Destroyed connection context.ldap2_139937138938208 2025-05-07T18:07:26Z DEBUG Starting external process 2025-05-07T18:07:26Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@UFREEIPA-TEST.service'] 2025-05-07T18:07:27Z DEBUG Process finished, return code=0 2025-05-07T18:07:27Z DEBUG stdout= 2025-05-07T18:07:27Z DEBUG stderr= 2025-05-07T18:07:27Z DEBUG Restart of dirsrv@UFREEIPA-TEST.service complete 2025-05-07T18:07:27Z DEBUG Created connection context.ldap2_139937138938208 2025-05-07T18:07:27Z DEBUG step duration: SID generation __restart_dirsrv 1.57 sec 2025-05-07T18:07:27Z DEBUG [7/8]: adding fallback group 2025-05-07T18:07:28Z DEBUG flushing ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket from SchemaCache 2025-05-07T18:07:28Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket conn= 2025-05-07T18:07:28Z DEBUG Starting external process 2025-05-07T18:07:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp63___i7c', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:07:28Z DEBUG Process finished, return code=0 2025-05-07T18:07:28Z DEBUG stdout=add cn: Default SMB Group add description: Fallback group for primary group RID, do not add users to this group add gidnumber: -1 add objectclass: top ipaobject posixgroup adding new entry "cn=Default SMB Group,cn=groups,cn=accounts,dc=ufreeipa,dc=test" modify complete 2025-05-07T18:07:28Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:07:28Z DEBUG step duration: SID generation __add_fallback_group 0.70 sec 2025-05-07T18:07:28Z DEBUG [8/8]: adding SIDs to existing users and groups 2025-05-07T18:07:28Z DEBUG Starting external process 2025-05-07T18:07:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpuk3ketl3', '-H', 'ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket', '-Y', 'EXTERNAL'] 2025-05-07T18:07:28Z DEBUG Process finished, return code=0 2025-05-07T18:07:28Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=ufreeipa,dc=test add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2025-05-07T18:07:28Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-UFREEIPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2025-05-07T18:07:28Z DEBUG This step may take considerable amount of time, please wait.. 2025-05-07T18:07:28Z DEBUG step duration: SID generation __add_sids 0.10 sec 2025-05-07T18:07:28Z DEBUG Done. 2025-05-07T18:07:28Z DEBUG service duration: SID generation 2.78 sec 2025-05-07T18:07:28Z DEBUG raw: update_host_cifs_keytabs 2025-05-07T18:07:28Z DEBUG raw: adtrust_is_enabled(version='2.254') 2025-05-07T18:07:28Z DEBUG adtrust_is_enabled(version='2.254') 2025-05-07T18:07:28Z DEBUG AD Trusts are not enabled on this server 2025-05-07T18:07:28Z DEBUG Changing admin password 2025-05-07T18:07:28Z DEBUG Starting external process 2025-05-07T18:07:28Z DEBUG args=['/usr/bin/ldappasswd', '-H', 'ldap://master.ufreeipa.test', '-ZZ', '-x', '-D', 'cn=Directory Manager', '-y', '/var/lib/ipa/tmp3ab5q5xy', '-T', '/var/lib/ipa/tmph8iskgv0', 'uid=admin,cn=users,cn=accounts,dc=ufreeipa,dc=test'] 2025-05-07T18:07:29Z DEBUG Process finished, return code=0 2025-05-07T18:07:29Z DEBUG stdout= 2025-05-07T18:07:29Z DEBUG stderr= 2025-05-07T18:07:29Z DEBUG ldappasswd done 2025-05-07T18:07:29Z DEBUG Configuring client side components 2025-05-07T18:07:29Z DEBUG Starting external process 2025-05-07T18:07:29Z DEBUG args=['/usr/sbin/ipa-client-install', '--on-master', '--unattended', '--domain', 'ufreeipa.test', '--server', 'master.ufreeipa.test', '--realm', 'UFREEIPA.TEST', '--hostname', 'master.ufreeipa.test', '--no-ntp'] 2025-05-07T18:07:47Z DEBUG Process finished, return code=0 2025-05-07T18:07:47Z DEBUG Client install duration: 18.198 2025-05-07T18:07:47Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2025-05-07T18:07:47Z DEBUG Set service ['KDC'] for master.ufreeipa.test to enabledService 2025-05-07T18:07:47Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2025-05-07T18:07:47Z DEBUG Set service ['KPASSWD'] for master.ufreeipa.test to enabledService 2025-05-07T18:07:47Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2025-05-07T18:07:47Z DEBUG Set service ['KEYS'] for master.ufreeipa.test to enabledService 2025-05-07T18:07:47Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2025-05-07T18:07:47Z DEBUG Set service ['CA'] for master.ufreeipa.test to enabledService 2025-05-07T18:07:47Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2025-05-07T18:07:47Z DEBUG Set service ['OTPD'] for master.ufreeipa.test to enabledService 2025-05-07T18:07:47Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2025-05-07T18:07:47Z DEBUG Set service ['HTTP'] for master.ufreeipa.test to enabledService 2025-05-07T18:07:47Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2025-05-07T18:07:47Z DEBUG Set service ['DNS'] for master.ufreeipa.test to enabledService 2025-05-07T18:07:47Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2025-05-07T18:07:47Z DEBUG Set service ['DNSKeySync'] for master.ufreeipa.test to enabledService 2025-05-07T18:07:47Z DEBUG raw: dns_update_system_records(version='2.254') 2025-05-07T18:07:47Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:47Z DEBUG raw: server_find(None, version='2.254', no_members=False, servrole='IPA master') 2025-05-07T18:07:47Z DEBUG server_find(None, all=False, raw=False, version='2.254', no_members=False, pkey_only=False, servrole=('IPA master',)) 2025-05-07T18:07:47Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.254') 2025-05-07T18:07:47Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.254') 2025-05-07T18:07:47Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.254') 2025-05-07T18:07:47Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.254', pkey_only=False) 2025-05-07T18:07:47Z DEBUG raw: server_role_find(None, server_server='master.ufreeipa.test', status='enabled', include_master=True, version='2.254') 2025-05-07T18:07:47Z DEBUG server_role_find(None, server_server='master.ufreeipa.test', status='enabled', include_master=True, all=False, raw=False, version='2.254') 2025-05-07T18:07:47Z DEBUG raw: dnszone_show(, version='2.254') 2025-05-07T18:07:47Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:47Z DEBUG raw: dnsrecord_del(, , del_all=True, version='2.254') 2025-05-07T18:07:47Z DEBUG dnsrecord_del(, , del_all=True, structured=False, raw=False, version='2.254') 2025-05-07T18:07:47Z DEBUG raw: dnsrecord_delentry(, (,), version='2.254') 2025-05-07T18:07:47Z DEBUG dnsrecord_delentry(, (,), continue=False, version='2.254') 2025-05-07T18:07:47Z DEBUG Name master.ufreeipa.test. resolved to {UnsafeIPAddress('10.0.169.172')} 2025-05-07T18:07:47Z DEBUG Adding CA IP 10.0.169.172 for master.ufreeipa.test. 2025-05-07T18:07:47Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"UFREEIPA.TEST"'], urirecord=['0 100 "krb5srv:m:tcp:master.ufreeipa.test."', '0 100 "krb5srv:m:udp:master.ufreeipa.test."'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:47Z DEBUG dnsrecord_mod(, , txtrecord=('"UFREEIPA.TEST"',), urirecord=('0 100 "krb5srv:m:tcp:master.ufreeipa.test."', '0 100 "krb5srv:m:udp:master.ufreeipa.test."'), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:47Z DEBUG update_entry modlist [(2, 'urirecord', [b'0 100 "krb5srv:m:tcp:master.ufreeipa.test."', b'0 100 "krb5srv:m:udp:master.ufreeipa.test."']), (1, 'txtrecord', [b'UFREEIPA.TEST']), (0, 'txtrecord', [b'"UFREEIPA.TEST"']), (2, 'idnstemplateattribute;cnamerecord', [b'_kerberos.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2025-05-07T18:07:47Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 master.ufreeipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:47Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 master.ufreeipa.test.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:47Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 389 master.ufreeipa.test.'], version='2.254') 2025-05-07T18:07:47Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 389 master.ufreeipa.test.',), force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:47Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:47Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:47Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2025-05-07T18:07:47Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master.ufreeipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:47Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master.ufreeipa.test.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 master.ufreeipa.test.'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 master.ufreeipa.test.',), force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master.ufreeipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master.ufreeipa.test.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 master.ufreeipa.test.'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 master.ufreeipa.test.',), force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master.ufreeipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master.ufreeipa.test.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 master.ufreeipa.test.'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 master.ufreeipa.test.',), force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master.ufreeipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master.ufreeipa.test.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:48Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 master.ufreeipa.test.'], version='2.254') 2025-05-07T18:07:48Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 master.ufreeipa.test.',), force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:49Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:49Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:49Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2025-05-07T18:07:49Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 master.ufreeipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:49Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 master.ufreeipa.test.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:49Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 464 master.ufreeipa.test.'], version='2.254') 2025-05-07T18:07:49Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 464 master.ufreeipa.test.',), force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:49Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:49Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:49Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2025-05-07T18:07:49Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 master.ufreeipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:49Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 master.ufreeipa.test.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:49Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 464 master.ufreeipa.test.'], version='2.254') 2025-05-07T18:07:49Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 464 master.ufreeipa.test.',), force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:49Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:49Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:49Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2025-05-07T18:07:49Z DEBUG raw: dnsrecord_mod(, , urirecord=['0 100 "krb5srv:m:tcp:master.ufreeipa.test."', '0 100 "krb5srv:m:udp:master.ufreeipa.test."'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:49Z DEBUG dnsrecord_mod(, , urirecord=('0 100 "krb5srv:m:tcp:master.ufreeipa.test."', '0 100 "krb5srv:m:udp:master.ufreeipa.test."'), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:49Z DEBUG raw: dnsrecord_add(, , urirecord=['0 100 "krb5srv:m:tcp:master.ufreeipa.test."', '0 100 "krb5srv:m:udp:master.ufreeipa.test."'], version='2.254') 2025-05-07T18:07:49Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, urirecord=('0 100 "krb5srv:m:tcp:master.ufreeipa.test."', '0 100 "krb5srv:m:udp:master.ufreeipa.test."'), force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:50Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.254') 2025-05-07T18:07:50Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:50Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kpasswd.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2025-05-07T18:07:50Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.169.172'], version='2.254') 2025-05-07T18:07:50Z DEBUG dnsrecord_mod(, , arecord=('10.0.169.172',), rights=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:50Z DEBUG raw: dnsrecord_add(, , arecord=['10.0.169.172'], version='2.254') 2025-05-07T18:07:50Z DEBUG dnsrecord_add(, , arecord=('10.0.169.172',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version='2.254') 2025-05-07T18:07:50Z DEBUG raw: location_find(None, version='2.254') 2025-05-07T18:07:50Z DEBUG location_find(None, all=False, raw=False, version='2.254', pkey_only=False) 2025-05-07T18:07:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:50Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:50Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2025-05-07T18:07:50Z DEBUG Enabling and restarting the IPA service 2025-05-07T18:07:50Z DEBUG Starting external process 2025-05-07T18:07:50Z DEBUG args=['/bin/systemctl', 'enable', 'ipa.service'] 2025-05-07T18:07:50Z DEBUG Process finished, return code=0 2025-05-07T18:07:50Z DEBUG stdout= 2025-05-07T18:07:50Z DEBUG stderr=Created symlink '/etc/systemd/system/multi-user.target.wants/ipa.service' → '/usr/lib/systemd/system/ipa.service'. 2025-05-07T18:07:50Z DEBUG Starting external process 2025-05-07T18:07:50Z DEBUG args=['/bin/systemctl', 'restart', 'ipa.service'] 2025-05-07T18:07:54Z DEBUG Process finished, return code=1 2025-05-07T18:07:54Z DEBUG stdout= 2025-05-07T18:07:54Z DEBUG stderr=Job for ipa.service failed because the control process exited with error code. See "systemctl status ipa.service" and "journalctl -xeu ipa.service" for details. 2025-05-07T18:07:54Z DEBUG File "/usr/lib/python3.13/site-packages/ipapython/admintool.py", line 219, in execute return_value = self.run() File "/usr/lib/python3.13/site-packages/ipapython/install/cli.py", line 343, in run return cfgr.run() ~~~~~~~~^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 360, in run return self.execute() ~~~~~~~~~~~~^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 386, in execute for rval in self._executor(): ~~~~~~~~~~~~~~^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 435, in __runner exc_handler(exc_info) ~~~~~~~~~~~^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 468, in _handle_execute_exception self._handle_exception(exc_info) ~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 458, in _handle_exception six.reraise(*exc_info) ~~~~~~~~~~~^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/six.py", line 724, in reraise raise value File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 425, in __runner step() ~~~~^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 419, in step_next return next(self.__gen) File "/usr/lib/python3.13/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) ~~~~~~~~~~~^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/six.py", line 724, in reraise raise value File "/usr/lib/python3.13/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 663, in _configure next(executor) ~~~~^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 435, in __runner exc_handler(exc_info) ~~~~~~~~~~~^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 468, in _handle_execute_exception self._handle_exception(exc_info) ~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 526, in _handle_exception self.__parent._handle_exception(exc_info) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 458, in _handle_exception six.reraise(*exc_info) ~~~~~~~~~~~^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/six.py", line 724, in reraise raise value File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 523, in _handle_exception super(ComponentBase, self)._handle_exception(exc_info) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 458, in _handle_exception six.reraise(*exc_info) ~~~~~~~~~~~^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/six.py", line 724, in reraise raise value File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 425, in __runner step() ~~~~^^ File "/usr/lib/python3.13/site-packages/ipapython/install/core.py", line 419, in step_next return next(self.__gen) File "/usr/lib/python3.13/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) ~~~~~~~~~~~^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/six.py", line 724, in reraise raise value File "/usr/lib/python3.13/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python3.13/site-packages/ipapython/install/common.py", line 65, in _install for unused in self._installer(self.parent): ~~~~~~~~~~~~~~~^^^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipaserver/install/server/__init__.py", line 654, in main master_install(self) ~~~~~~~~~~~~~~^^^^^^ File "/usr/lib/python3.13/site-packages/ipaserver/install/server/install.py", line 278, in decorated func(installer) ~~~~^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipaserver/install/server/install.py", line 1082, in install services.knownservices.ipa.enable() ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^ File "/usr/lib/python3.13/site-packages/ipaplatform/redhat/services.py", line 168, in enable self.restart(instance_name) ~~~~~~~~~~~~^^^^^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipaplatform/base/services.py", line 341, in restart self._restart_base(instance_name, "restart", ~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^ capture_output, wait) ^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipaplatform/base/services.py", line 326, in _restart_base ipautil.run([paths.SYSTEMCTL, operation, ~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ self.service_instance(instance_name)], ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ skip_output=not capture_output) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3.13/site-packages/ipapython/ipautil.py", line 607, in run raise CalledProcessError( p.returncode, arg_string, output_log, error_log ) 2025-05-07T18:07:54Z DEBUG The ipa-server-install command failed, exception: CalledProcessError: CalledProcessError(Command ['/bin/systemctl', 'restart', 'ipa.service'] returned non-zero exit status 1: 'Job for ipa.service failed because the control process exited with error code.\nSee "systemctl status ipa.service" and "journalctl -xeu ipa.service" for details.\n') 2025-05-07T18:07:54Z ERROR CalledProcessError(Command ['/bin/systemctl', 'restart', 'ipa.service'] returned non-zero exit status 1: 'Job for ipa.service failed because the control process exited with error code.\nSee "systemctl status ipa.service" and "journalctl -xeu ipa.service" for details.\n') 2025-05-07T18:07:54Z ERROR The ipa-server-install command failed. See /var/log/ipaserver-install.log for more information